fzib.at
HTML metadata
Technology
- Server
- nginx
Third-party hosts loaded (4)
- static.uni-graz.at×15
- webcmp.uni-graz.at×2
- webstat.uni-graz.at×2
- oembed.uni-graz.at×1
DNS records live
- NS
-
- ns49.internic.at
- ns501.internic.at
- ns57.internic.at
- ns6.internic.at
- ns81.internic.at
- MX
-
- 100 mail20.internic.at
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 31 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer- x-frame-options
deny- permissions-policy
accelerometer=(self "https://unitube.uni-graz.at" "https://open.spotify.com" "https://www.vimeo.com" "https://www.youtube.com"), autoplay=(self "https://unitube.uni-graz.at" "https://open.spotify.com" "https://www.vimeo.com" "https://www.youtube.com"), clipboard-write=(self "https://unitube.uni-graz.at" "https://open.spotify.com" "https://www.vimeo.com" "https://www.youtube.com"), encrypted-media=(self "https://unitube.uni-graz.at" "https://open.spotify.com" "https://www.vimeo.com" "https://www.youtube.com"), fullscreen=(self "https://unitube.uni-graz.at" "https://open.spotify.com" "https://www.vimeo.com" "https://www.youtube.com"), gyroscope=(self "https://unitube.uni-graz.at" "https://open.spotify.com" "https://www.vimeo.com" "https://www.youtube.com"), picture-in-picture=(self "https://unitube.uni-graz.at" "https://open.spotify.com" "https://www.vimeo.com" "https://www.youtube.com"), web-share=(self "https://unitube.uni-graz.at" "https://open.spotify.com" "https://www.vimeo.com" "ht- x-content-type-options
nosniff- content-security-policy
default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://static.uni-graz.at https://webcmp.uni-graz.at https://oembed.uni-graz.at https://bezahlung.uni-graz.at https://webstat.uni-graz.at https://ask.uni-graz.at https://beta.ug.aios.dev https://*.googletagmanager.com https://connect.facebook.net blob: 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: https://static.uni-graz.at https://bezahlung.uni-graz.at https://online.uni-graz.at https://screenshot.uni-graz.at https://webstat.uni-graz.at https://ask.uni-graz.at https://beta.ug.aios.dev https://*.google-analytics.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.at https://pagead2.googlesyndication.com https://www.facebook.com; base-uri 'self'; frame-src 'self' https://static.uni-graz.at https://webstat.uni-graz.at https://unitube.uni-graz.at https://*.googletagmanager.com https://td.doubleclick.net https://open.spotify.com https
Links to (3)
Linked from (1)
- phst.at×1