hogum
kaeltebringer.de

kaeltebringer.de security report

Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.

55risk

Elevated

Several issues worth triaging this week.

0Critical
1High
5Medium
8Low
2Info
Collected 23.2sfrom cache
  1. Certificate Transparency9
  2. DNS resolution17
  3. Network ownership0
  4. CDN / WAF detection0
  5. Exposed ports & CVEs57
  6. Registration
  7. DNS posture2
  8. Email authentication1
  9. Certificate
  10. Security headers4
  11. Archived URLs
  12. Analysis16
  • noteFound 17 addresses; enriching the first 12.
  • noteCertificate inspection is unavailable in this runtime.
  • noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
  • noteCDN/WAF detection is unavailable in this runtime.
  • noteNo registration data: RDAP has no record at this level.
  • note3 hosts were identified as CDN/edge infrastructure from ASN ownership rather than a cdncheck fingerprint.
final https://www.kaeltebringer.de/status 200time 1874msstack cloudflare
  • http:// redirects to https://
  • !Strict-Transport-Security
    max-age=7889238
  • Content-Security-Policy
    block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests;
  • Clickjacking protection
    DENY
  • X-Content-Type-Options
    nosniff
  • Referrer-Policy
  • Permissions-Policyoptional
  • security.txt publishedoptional — tells researchers where to report bugs
  • Cookie _shopify_y
    no Secure · no HttpOnly · SameSite=lax
  • Cookie _shopify_s
    no Secure · no HttpOnly · SameSite=lax
  • Cookie localization
    no Secure · no HttpOnly · SameSite=lax
  • Cookie cart_currency
    no Secure · no HttpOnly · SameSite=lax
  • Cookie _shopify_essential
    Secure · HttpOnly · SameSite=lax
  • Cookie _shopify_analytics
    Secure · HttpOnly · SameSite=lax
  • Cookie _shopify_marketing
    Secure · HttpOnly · SameSite=lax
  • Receives mail via 1 server
  • SPF
    no record
  • !DMARCp=none
    v=DMARC1; p=none
  • !MTA-STSinbound mail can be downgraded to plaintext
AddressPortsCVEsEdgeNetwork
23.227.38.74
80443205220532082208320862087+5
0Cloudflare~
23.227.38.32
80443205220532082208320862087+5
0Cloudflare~
162.159.140.147
80443205220532082208320862087+5
0Cloudflare~
216.150.16.65
80443
0direct
216.150.1.65
80443
0direct
216.150.16.129
80443
0direct
216.150.1.129
80443
0direct
151.115.15.217
80443
0direct
65.9.130.62
80443
0direct
65.9.130.74
80443
0direct
65.9.130.68
80443
0direct
65.9.130.73
80443
0direct
Archived URLs

Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.