hogum
buzzfeed.de

buzzfeed.de security report

Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.

70risk

Elevated

Several issues worth triaging this week.

0Critical
2High
5Medium
5Low
2Info
Collected 6.5sfrom cache
  1. Certificate Transparency10
  2. DNS resolution15
  3. Network ownership0
  4. CDN / WAF detection0
  5. Exposed ports & CVEs51
  6. Registration
  7. DNS posture4
  8. Email authentication1
  9. Certificate
  10. Security headers0
  11. Archived URLs
  12. Analysis14
  • noteCertificate inspection is unavailable in this runtime.
  • noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
  • noteCDN/WAF detection is unavailable in this runtime.
  • noteNo registration data: RDAP has no record at this level.
  • note3 hosts were identified as CDN/edge infrastructure from ASN ownership rather than a cdncheck fingerprint.
final https://www.buzzfeed.de/status 200time 4117msstack cloudflare
  • http:// redirects to https://
  • Strict-Transport-Security
  • Content-Security-Policy
  • Clickjacking protection
  • X-Content-Type-Options
  • Referrer-Policy
  • Permissions-Policyoptional
  • security.txt publishedoptional — tells researchers where to report bugs
  • Cookie cua_uuid
    no Secure · no HttpOnly · no SameSite
  • Cookie new_user
    no Secure · no HttpOnly · no SameSite
AddressPortsCVEsEdgeNetwork
104.26.14.31
80443205220532082208320862087+5
0Cloudflare~
172.67.71.184
80443205220532082208320862087+5
0Cloudflare~
104.26.15.31
80443205220532082208320862087+5
0Cloudflare~
91.234.30.113
80443
0direct
18.159.220.84
80443
0direct
52.58.107.174
80443
0direct
18.158.98.81
80443
0direct
18.155.68.104
80
0direct
18.155.68.66
80
0direct
18.155.68.112
80
0direct
18.155.68.9
80
0direct
Archived URLs

Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.