nuug.no
HTML metadata
Technology
- Server
- Apache
Contact
Registration
- Registrar
- Domeneshop AS
- Created
- 1999-11-14
- Updated
- 2026-02-12
- Name servers
-
- ns1.nuug.no
- ns.hyp.net
DNS records
Email authentication weak
- SPF
-
v=spf1 a mx ip4:185.181.61.63 ip4:158.36.191.128/25 ip6:2a03:94e0:182c::1 include:spf.uio.no -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 54 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.youtube.com *.openstreetmap.org *.vimeo.com *.frikanalen.no *.nuug.no yewtu.be *.kjemi.uio.no *.oreilly.com *.skolelinux.de *.googleapis.com remarkjs.com *.gstatic.com api.flattr.com; img-src 'self' twitter-badges.s3.amazonaws.com nuug.no data: secure.gravatar.com blob:; script-src-elem 'self' 'unsafe-inline' yewtu.be remarkjs.com *.flattr.com digg.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' yewtu.be blob: *.googleapis.com *.gstatic.com; style-src 'self' 'unsafe-inline' *.googleapis.com; connect-src 'self' *.nuug.no *.googleapis.com; worker-src 'self' blob:; frame-src 'self' *.youtube.com blob:; frame-ancestors 'self' nuug.no; report-uri /csp-report-endpoint;- strict-transport-security
max-age=10886400; includeSubDomains; preload
Links to (5)
- apache.org×1
- debian.org×1
- fiksgatami.no×1
- oftc.net×1
- usenix.org×1