c0v.co
Technology
- Server
- nginx
DNS records live
- NS
-
- a8.uberns.com
- b8.uberns.com
- MX
-
- 10 mx01.mi.com.co
- 5 mx03.mi.com.co
- TXT
-
453mf18m6kpb08w0980q5f5q2ng4c70v.
Email authentication weak
- SPF
-
v=spf1 include:_spf.mi.com.co ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 47 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- weak content type protection
Header values
- referrer-policy
strict-origin, strict-origin- x-frame-options
SAMEORIGIN, SAMEORIGIN- permissions-policy
geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=(), geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()- x-content-type-options
nosniff, nosniff- content-security-policy
default-src 'self'; font-src * data:; img-src * data:; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; frame-src 'self', default-src 'self'; font-src * data:; img-src * data:; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; frame-src 'self'- strict-transport-security
max-age=31536000; includeSubDomains, max-age=31536000; includeSubDomains