altolashop.ch
HTML metadata
Technology
- Server
- Apache
- CMS
- Drupal
- jQuery
- 1.10.1 known XSS (<3.5)
DNS records live
- NS
-
- dns1.aare-net.ch
- dns2.aare-net.ch
- dns3.aare-net.ch
- dns4.aare-net.ch
- MX
-
- 1 mail.altolashop.ch
- Verified for
-
Email authentication partial
- SPF
-
v=spf1 a mx ptr a:srv.altolashop.ch a:iris.aare-net.ch a:hermes.aare-net.ch include:spf.crsend.com ip4:5.9.61.71/32 ip4:167.99.240.209/32 ip4:178.63.40.12/32 ip4:91.217.140.0/24 -allstrict (-all) - DMARC
-
v=DMARC1; p=nonepolicy: none (monitoring only) - DKIM
-
- mail:
v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnXUoadqu+AC9HPpiQufPoUgzHwp2fgJJ2Ew1YHPF3ZGfX1i4mKu4liPiqIOQvj/MiK5l…
selectors probed - mail:
Certificate (current)
R13
Expires in 71 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- CSP allows unsafe inline scripts/styles
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
default-src 'self' 'unsafe-inline' data: bso.altolashop.ch; upgrade-insecure-requests; frame-ancestors 'self'- strict-transport-security
max-age=63072000; includeSubDomains; preload
Links to (3)
- google.com×1
- apple.com×1
- altola.ch×1