hogum
ctk.at

ctk.at security report

Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.

82risk

Critical

Exposed services or known CVEs need attention now.

1Critical
1High
5Medium
10Low
2Info
Collected 16.1sfrom cache
  1. Certificate Transparency301
  2. DNS resolution6
  3. Network ownership0
  4. CDN / WAF detection0
  5. Exposed ports & CVEs17
  6. Registration
  7. DNS posture4
  8. Email authentication2
  9. Certificate
  10. Security headers0
  11. Archived URLs
  12. Analysis19
  • noteFound 301 hostnames; this runtime allows 50 outbound requests per scan, so the 21 most likely to matter were resolved.
  • noteCertificate inspection is unavailable in this runtime.
  • noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
  • noteCDN/WAF detection is unavailable in this runtime.
  • noteNo registration data: RDAP has no record at this level.
final https://www.ctk.at/status 200time 4516msstack cloudflare · PHP/7.4.33 · WordPress 6.6.7
  • http:// redirects to https://
  • Strict-Transport-Security
  • Content-Security-Policy
  • Clickjacking protection
  • X-Content-Type-Options
  • Referrer-Policy
  • Permissions-Policyoptional
  • security.txt publishedoptional — tells researchers where to report bugs
  • Receives mail via 2 servers
  • !SPFends in ~all
    v=spf1 +mx ip4:88.117.145.162 a:o.ctk.at include:spf.ledl.net ~all
  • DMARCp=quarantine
    v=DMARC1; p=quarantine
  • !MTA-STSinbound mail can be downgraded to plaintext
AddressPortsCVEsEdgeNetwork
213.145.225.110
212580110143443465587+2
98direct
51.91.152.213
5380111443330627015
0direct
185.46.122.164
443
0direct
78.132.27.106none known0direct
Archived URLs

Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.