hogum
fortum.pl

fortum.pl security report

Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.

66risk

Elevated

Several issues worth triaging this week.

1Critical
0High
2Medium
21Low
1Info
Collected 7.8sfrom cache
Domain
unavailable
  1. Certificate Transparency268
  2. DNS resolution17
  3. Network ownership0
  4. CDN / WAF detection0
  5. Exposed ports & CVEs14
  6. Registration
  7. DNS posture4
  8. Email authentication2
  9. Certificate
  10. Security headers5
  11. Archived URLs
  12. Analysis25
  • noteFound 268 hostnames; this runtime allows 50 outbound requests per scan, so the 21 most likely to matter were resolved.
  • noteCertificate inspection is unavailable in this runtime.
  • noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
  • noteCDN/WAF detection is unavailable in this runtime.
  • noteRegistration did not complete (Too many subrequests by single Worker invocation. To configure this limit, refer to https://developers.cloudflare.com/workers/wrangler/configuration/#limits). Results below are partial.
final https://www.fortum.pl/status 200time 1381msstack cloudflare
  • http:// redirects to https://port 80 did not answer
  • Strict-Transport-Security
    max-age=31557600; includeSubDomains
  • Content-Security-Policy
    upgrade-insecure-requests; default-src https: data: 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'self' *.wdr.io *.fortum.com *.fortum.se *.fortum.no *.fortum…
  • Clickjacking protection
    SAMEORIGIN
  • X-Content-Type-Options
    nosniff
  • Referrer-Policy
    no-referrer, strict-origin-when-cross-origin
  • Permissions-Policyoptional
  • security.txt publishedoptional — tells researchers where to report bugs
  • Cookie country
    no Secure · no HttpOnly · no SameSite
  • Receives mail via 1 server
  • SPFends in -all
    v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:spf.protection.outlook.com -all
  • DMARCp=reject
    v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email,mailto:dmarc_reporting@fortum.com; ruf=mailto:dmarc_reporting@fortum.com; fo=1
  • MTA-STSinbound mail must use TLS
AddressPortsCVEsEdgeNetwork
4.245.3.129
80443
0direct
199.36.158.100
80443
0direct
151.101.2.137
80443
0direct
151.101.66.137
80443
0direct
151.101.130.137
80443
0direct
151.101.194.137
80443
12direct
4.210.211.41
80443
0direct
10.129.190.183none known0direct
10.129.190.36none known0direct
Archived URLs

Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.