hogum
aarome.org

aarome.org security report

Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.

78risk

Critical

Exposed services or known CVEs need attention now.

1Critical
3High
5Medium
5Low
2Info
Collected 53.7sfrom cache
Domain
unavailable
  1. Certificate Transparency22
  2. DNS resolution32
  3. Network ownership0
  4. CDN / WAF detection0
  5. Exposed ports & CVEs71
  6. Registration
  7. DNS posture3
  8. Email authentication2
  9. Certificate
  10. Security headers3
  11. Archived URLs
  12. Analysis16
  • noteFound 22 hostnames; this runtime allows 50 outbound requests per scan, so the 21 most likely to matter were resolved.
  • noteFound 21 addresses; enriching the first 12.
  • noteCertificate inspection is unavailable in this runtime.
  • noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
  • noteCDN/WAF detection is unavailable in this runtime.
  • noteRegistration did not complete (Too many subrequests by single Worker invocation. To configure this limit, refer to https://developers.cloudflare.com/workers/wrangler/configuration/#limits). Results below are partial.
  • note4 hosts were identified as CDN/edge infrastructure from ASN ownership rather than a cdncheck fingerprint.
final https://aarome.org/status 200time 805msstack cloudflare · Drupal 10 (https://www.drupal.org)
  • http:// redirects to https://port 80 did not answer
  • Strict-Transport-Security
  • Content-Security-Policy
    font-src 'self' data: https://themes.googleusercontent.com; img-src 'self' data: https://www.google-analytics.com https://www.googletagmanager.com; object-src '…
  • Clickjacking protection
    SAMEORIGIN
  • X-Content-Type-Options
    nosniff
  • Referrer-Policy
  • Permissions-Policyoptional
  • security.txt publishedoptional — tells researchers where to report bugs
  • Receives mail via 2 servers
  • SPFends in -all
    v=spf1 ip4:95.110.249.229 include:_spf.google.com a:smtp.areasrl.com a:aarome.bywatersolutions.com include:spf.mandrillapp.com include:sendgrid.net include:amazonses.com include:spf.protection.outlook.com include:outboundmail.blackbaud.net include:aspmx.pardot.com include:_spf.salesforce.com include:spf1.formassembly.com -all
  • DMARCp=quarantine
    v=DMARC1; p=quarantine; sp=quarantine; pct=100;
  • !MTA-STSinbound mail can be downgraded to plaintext
AddressPortsCVEsEdgeNetwork
104.18.124.73
80443205220532082208320862087+5
0Cloudflare~
104.18.197.95
80443205220532082208320862087+5
0Cloudflare~
104.18.1.36
80443205220532082208320862087+5
0Cloudflare~
104.18.0.36
80443205220532082208320862087+5
0Cloudflare~
97.107.135.178
258044310256
2direct
185.3.93.228
2580443
2direct
170.187.131.209
2580443
2direct
54.83.63.20
80443
76direct
185.255.186.51
80443
0direct
13.215.239.219
80443
0direct
52.74.6.109
80443
0direct
80.211.68.172
443
0direct
Archived URLs

Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.