Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
  • Loading branch information
rhanka committed Jul 9, 2023
1 parent 204fe82 commit 5bdaa77
Show file tree
Hide file tree
Showing 15 changed files with 2,324 additions and 2,109 deletions.
24 changes: 12 additions & 12 deletions results/aHR0cHM6Ly9kZWNlcy5tYXRjaGlkLmlv/404.json
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@
"href": "https://deces.matchid.io/"
},
"link": "https://deces.matchid.io/",
"line": "--2023-07-02 01:17:28-- https://deces.matchid.io/",
"line": "--2023-07-09 01:19:03-- https://deces.matchid.io/",
"broken": false
},
{
Expand All @@ -35,7 +35,7 @@
"href": "https://deces.matchid.io/robots.txt"
},
"link": "https://deces.matchid.io/robots.txt",
"line": "--2023-07-02 01:17:29-- https://deces.matchid.io/robots.txt",
"line": "--2023-07-09 01:19:04-- https://deces.matchid.io/robots.txt",
"broken": false
},
{
Expand All @@ -54,7 +54,7 @@
"href": "https://deces.matchid.io/favicon.svg"
},
"link": "https://deces.matchid.io/favicon.svg",
"line": "--2023-07-02 01:17:29-- https://deces.matchid.io/favicon.svg",
"line": "--2023-07-09 01:19:04-- https://deces.matchid.io/favicon.svg",
"broken": false
},
{
Expand All @@ -73,7 +73,7 @@
"href": "https://deces.matchid.io/favicon-apple.png"
},
"link": "https://deces.matchid.io/favicon-apple.png",
"line": "--2023-07-02 01:17:29-- https://deces.matchid.io/favicon-apple.png",
"line": "--2023-07-09 01:19:04-- https://deces.matchid.io/favicon-apple.png",
"broken": false
},
{
Expand All @@ -92,7 +92,7 @@
"href": "https://deces.matchid.io/manifest.json"
},
"link": "https://deces.matchid.io/manifest.json",
"line": "--2023-07-02 01:17:29-- https://deces.matchid.io/manifest.json",
"line": "--2023-07-09 01:19:04-- https://deces.matchid.io/manifest.json",
"broken": false
},
{
Expand All @@ -111,7 +111,7 @@
"href": "https://deces.matchid.io/css/global.css"
},
"link": "https://deces.matchid.io/css/global.css",
"line": "--2023-07-02 01:17:30-- https://deces.matchid.io/css/global.css",
"line": "--2023-07-09 01:19:05-- https://deces.matchid.io/css/global.css",
"broken": false
},
{
Expand All @@ -130,7 +130,7 @@
"href": "https://deces.matchid.io/css/matchid.min.css"
},
"link": "https://deces.matchid.io/css/matchid.min.css",
"line": "--2023-07-02 01:17:30-- https://deces.matchid.io/css/matchid.min.css",
"line": "--2023-07-09 01:19:05-- https://deces.matchid.io/css/matchid.min.css",
"broken": false
},
{
Expand All @@ -149,7 +149,7 @@
"href": "https://deces.matchid.io/build/module/bundle.css"
},
"link": "https://deces.matchid.io/build/module/bundle.css",
"line": "--2023-07-02 01:17:30-- https://deces.matchid.io/build/module/bundle.css",
"line": "--2023-07-09 01:19:05-- https://deces.matchid.io/build/module/bundle.css",
"broken": false
},
{
Expand All @@ -168,7 +168,7 @@
"href": "https://deces.matchid.io/js/matchid.min.js"
},
"link": "https://deces.matchid.io/js/matchid.min.js",
"line": "--2023-07-02 01:17:30-- https://deces.matchid.io/js/matchid.min.js",
"line": "--2023-07-09 01:19:05-- https://deces.matchid.io/js/matchid.min.js",
"broken": false
},
{
Expand All @@ -187,7 +187,7 @@
"href": "https://deces.matchid.io/cdn-cgi/scripts/7d0fa10a/cloudflare-static/rocket-loader.min.js"
},
"link": "https://deces.matchid.io/cdn-cgi/scripts/7d0fa10a/cloudflare-static/rocket-loader.min.js",
"line": "--2023-07-02 01:17:31-- https://deces.matchid.io/cdn-cgi/scripts/7d0fa10a/cloudflare-static/rocket-loader.min.js",
"line": "--2023-07-09 01:19:06-- https://deces.matchid.io/cdn-cgi/scripts/7d0fa10a/cloudflare-static/rocket-loader.min.js",
"broken": false
},
{
Expand All @@ -206,7 +206,7 @@
"href": "https://deces.matchid.io/css/layers.svg"
},
"link": "https://deces.matchid.io/css/layers.svg",
"line": "--2023-07-02 01:17:31-- https://deces.matchid.io/css/layers.svg",
"line": "--2023-07-09 01:19:06-- https://deces.matchid.io/css/layers.svg",
"broken": false
},
{
Expand All @@ -225,7 +225,7 @@
"href": "https://deces.matchid.io/css/images/marker-icon.png"
},
"link": "https://deces.matchid.io/css/images/marker-icon.png",
"line": "--2023-07-02 01:17:31-- https://deces.matchid.io/css/images/marker-icon.png",
"line": "--2023-07-09 01:19:06-- https://deces.matchid.io/css/images/marker-icon.png",
"broken": false
}
],
Expand Down
1 change: 1 addition & 0 deletions results/aHR0cHM6Ly9kZWNlcy5tYXRjaGlkLmlv/http.json
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
{"url":"https://deces.matchid.io","algorithm_version":2,"end_time":"Sun, 09 Jul 2023 01:20:59 GMT","grade":"C+","hidden":false,"likelihood_indicator":"MEDIUM","response_headers":{"CF-Cache-Status":"DYNAMIC","CF-RAY":"7e3cbf5c784b980b-SJC","Connection":"keep-alive","Content-Encoding":"gzip","Content-Security-Policy":"default-src 'self';script-src 'self' 'unsafe-inline' static.cloudflareinsights.com ajax.cloudflare.com www.googletagmanager.com www.google-analytics.com pagead2.googlesyndication.com partner.googleadservices.com tpc.googlesyndication.com www.googletagservices.com adservice.google.com adservice.google.fr;style-src https: 'self' 'unsafe-inline';font-src 'self' data:;img-src 'self' a.basemaps.cartocdn.com b.basemaps.cartocdn.com c.basemaps.cartocdn.com upload.wikimedia.org pagead2.googlesyndication.com www.google-analytics.com stats.g.doubleclick.net www.google.fr;connect-src 'self' www.data.gouv.fr cloudflareinsights.com www.google-analytics.com region1.analytics.google.com stats.g.doubleclick.net pagead2.googlesyndication.com; frame-src 'self' www.google.com google.com googleads.g.doubleclick.net tpc.googlesyndication.com","Content-Type":"text/html","Date":"Sun, 09 Jul 2023 01:20:58 GMT","Feature-Policy":"geolocation 'none';midi 'none';sync-xhr 'none';microphone 'none';camera 'none';magnetometer 'none';gyroscope 'self';accelerometer 'self';fullscreen 'self';payment 'none';","Last-Modified":"Thu, 29 Jun 2023 01:07:33 GMT","NEL":"{\"success_fraction\":0,\"report_to\":\"cf-nel\",\"max_age\":604800}","Referrer-Policy":"same-origin","Report-To":"{\"endpoints\":[{\"url\":\"https:\\/\\/a.nel.cloudflare.com\\/report\\/v3?s=u80GZU6Jp9cvLR9OnaMUDU3wJ%2BwNhyZrvKoklwiu4zWsKdhc1BePKkm6Mw2BROrcVNpPpAqsINvnsX2ERmuDqve3cCbBBZxRZGBm1BhfH7euX2qvsx4ko1PPgmNiGhXLtJENiWRLq5boU0BKm8Mr\"}],\"group\":\"cf-nel\",\"max_age\":604800}","Server":"cloudflare","Strict-Transport-Security":"max-age=15552000; includeSubDomains; preload","Transfer-Encoding":"chunked","X-Content-Type-Options":"nosniff","X-Frame-Options":"*.matchid.io","X-XSS-Protection":"1; mode=block","alt-svc":"h3=\":443\"; ma=86400"},"scan_id":39519615,"score":60,"start_time":"Sun, 09 Jul 2023 01:20:56 GMT","state":"FINISHED","status_code":200,"tests_failed":2,"tests_passed":10,"tests_quantity":12,"details":{"content-security-policy":{"expectation":"csp-implemented-with-no-unsafe","name":"content-security-policy","output":{"data":{"connect-src":["stats.g.doubleclick.net","www.data.gouv.fr","region1.analytics.google.com","cloudflareinsights.com","pagead2.googlesyndication.com","www.google-analytics.com","'self'"],"default-src":["'self'"],"font-src":["'self'","data:"],"frame-src":["www.google.com","google.com","googleads.g.doubleclick.net","tpc.googlesyndication.com","'self'"],"img-src":["a.basemaps.cartocdn.com","stats.g.doubleclick.net","www.google.fr","c.basemaps.cartocdn.com","b.basemaps.cartocdn.com","pagead2.googlesyndication.com","www.google-analytics.com","'self'","upload.wikimedia.org"],"script-src":["www.googletagmanager.com","adservice.google.fr","tpc.googlesyndication.com","adservice.google.com","pagead2.googlesyndication.com","partner.googleadservices.com","static.cloudflareinsights.com","www.googletagservices.com","www.google-analytics.com","'self'","'unsafe-inline'","ajax.cloudflare.com"],"style-src":["'self'","https:","'unsafe-inline'"]},"http":true,"meta":false,"numPolicies":1,"policy":{"antiClickjacking":false,"defaultNone":false,"insecureBaseUri":true,"insecureFormAction":true,"insecureSchemeActive":false,"insecureSchemePassive":false,"strictDynamic":false,"unsafeEval":false,"unsafeInline":true,"unsafeInlineStyle":true,"unsafeObjects":false}},"pass":false,"result":"csp-implemented-with-unsafe-inline","score_description":"Content Security Policy (CSP) implemented unsafely. This includes 'unsafe-inline' or data: inside script-src, overly broad sources such as https: inside object-src or script-src, or not restricting the sources for object-src or script-src.","score_modifier":-20},"contribute":{"expectation":"contribute-json-only-required-on-mozilla-properties","name":"contribute","output":{"data":null},"pass":true,"result":"contribute-json-only-required-on-mozilla-properties","score_description":"Contribute.json isn't required on websites that don't belong to Mozilla","score_modifier":0},"cookies":{"expectation":"cookies-secure-with-httponly-sessions","name":"cookies","output":{"data":null,"sameSite":null},"pass":true,"result":"cookies-not-found","score_description":"No cookies detected","score_modifier":0},"cross-origin-resource-sharing":{"expectation":"cross-origin-resource-sharing-not-implemented","name":"cross-origin-resource-sharing","output":{"data":{"acao":null,"clientaccesspolicy":null,"crossdomain":null}},"pass":true,"result":"cross-origin-resource-sharing-not-implemented","score_description":"Content is not visible via cross-origin resource sharing (CORS) files or headers","score_modifier":0},"public-key-pinning":{"expectation":"hpkp-not-implemented","name":"public-key-pinning","output":{"data":null,"includeSubDomains":false,"max-age":null,"numPins":null,"preloaded":false},"pass":true,"result":"hpkp-not-implemented","score_description":"HTTP Public Key Pinning (HPKP) header not implemented","score_modifier":0},"redirection":{"expectation":"redirection-to-https","name":"redirection","output":{"destination":"https://deces.matchid.io/","redirects":true,"route":["http://deces.matchid.io/","https://deces.matchid.io/"],"status_code":200},"pass":true,"result":"redirection-to-https","score_description":"Initial redirection is to HTTPS on same host, final destination is HTTPS","score_modifier":0},"referrer-policy":{"expectation":"referrer-policy-private","name":"referrer-policy","output":{"data":"same-origin","http":true,"meta":false},"pass":true,"result":"referrer-policy-private","score_description":"Referrer-Policy header set to \"no-referrer\", \"same-origin\", \"strict-origin\" or \"strict-origin-when-cross-origin\"","score_modifier":5},"strict-transport-security":{"expectation":"hsts-implemented-max-age-at-least-six-months","name":"strict-transport-security","output":{"data":"max-age=15552000; includeSubDomains; preload","includeSubDomains":true,"max-age":15552000,"preload":true,"preloaded":false},"pass":true,"result":"hsts-implemented-max-age-at-least-six-months","score_description":"HTTP Strict Transport Security (HSTS) header set to a minimum of six months (15768000)","score_modifier":0},"subresource-integrity":{"expectation":"sri-implemented-and-external-scripts-loaded-securely","name":"subresource-integrity","output":{"data":{"https://static.cloudflareinsights.com/beacon.min.js/v52afc6f149f6479b8c77fa569edb01181681764108816":{"crossorigin":"anonymous","integrity":"sha512-jGCTpDpBAYDGNYR5ztKt4BQPGef1P0giN6ZGVUi835kFF88FOmmn8jBQWNgrNd8g/Yu421NdgWhwQoaOPFflDw=="}}},"pass":true,"result":"sri-implemented-and-external-scripts-loaded-securely","score_description":"Subresource Integrity (SRI) is implemented and all scripts are loaded securely","score_modifier":5},"x-content-type-options":{"expectation":"x-content-type-options-nosniff","name":"x-content-type-options","output":{"data":"nosniff"},"pass":true,"result":"x-content-type-options-nosniff","score_description":"X-Content-Type-Options header set to \"nosniff\"","score_modifier":0},"x-frame-options":{"expectation":"x-frame-options-sameorigin-or-deny","name":"x-frame-options","output":{"data":"*.matchid.io"},"pass":false,"result":"x-frame-options-header-invalid","score_description":"X-Frame-Options (XFO) header cannot be recognized","score_modifier":-20},"x-xss-protection":{"expectation":"x-xss-protection-1-mode-block","name":"x-xss-protection","output":{"data":"1; mode=block"},"pass":true,"result":"x-xss-protection-enabled-mode-block","score_description":"X-XSS-Protection header set to \"1; mode=block\"","score_modifier":0}}}

Large diffs are not rendered by default.

3,026 changes: 1,672 additions & 1,354 deletions results/aHR0cHM6Ly9kZWNlcy5tYXRjaGlkLmlv/lhr.json

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions results/aHR0cHM6Ly9kZWNlcy5tYXRjaGlkLmlv/nmapvuln.gnmap
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# Nmap 7.92 scan initiated Sun Jul 2 01:21:33 2023 as: nmap -sV --script vulners --script-args mincvss=5.0 -oA /data/nmapvuln deces.matchid.io
# Nmap 7.92 scan initiated Sun Jul 9 01:23:36 2023 as: nmap -sV --script vulners --script-args mincvss=5.0 -oA /data/nmapvuln deces.matchid.io
Host: 104.21.64.91 () Status: Up
Host: 104.21.64.91 () Ports: 80/open/tcp//http//Cloudflare http proxy/, 443/open/tcp//ssl|http//Cloudflare http proxy/, 8080/open/tcp//http//Cloudflare http proxy/, 8443/open/tcp//ssl|http//Cloudflare http proxy/ Ignored State: filtered (996)
# Nmap done at Sun Jul 2 01:22:12 2023 -- 1 IP address (1 host up) scanned in 38.96 seconds
# Nmap done at Sun Jul 9 01:24:15 2023 -- 1 IP address (1 host up) scanned in 39.42 seconds
8 changes: 4 additions & 4 deletions results/aHR0cHM6Ly9kZWNlcy5tYXRjaGlkLmlv/nmapvuln.html
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@
<h1>Scan Report<br><small>Nmap 7.92</small>
</h1>
<pre style="white-space:pre-wrap; word-wrap:break-word;">nmap -sV --script vulners --script-args mincvss=5.0 -oA /data/nmapvuln deces.matchid.io</pre>
<p class="lead">Sun Jul 2 01:21:33 2023 – Sun Jul 2 01:22:12 2023<br>1 hosts scanned.
<p class="lead">Sun Jul 9 01:23:36 2023 – Sun Jul 9 01:24:15 2023<br>1 hosts scanned.
1 hosts up.
0 hosts down.
</p>
Expand Down Expand Up @@ -130,10 +130,10 @@ <h4>Ports</h4>
<td title="Extra Info"></td>
</tr>
<tr><td colspan="7">
<a href="https://nvd.nist.gov/vuln/search/results?form_type=Advanced&amp;cves=on&amp;cpe_version="></a><h5>http-trane-info</h5>
<pre style="white-space:pre-wrap; word-wrap:break-word;">Problem with XML parsing of /evox/about</pre>
<h5>http-server-header</h5>
<a href="https://nvd.nist.gov/vuln/search/results?form_type=Advanced&amp;cves=on&amp;cpe_version="></a><h5>http-server-header</h5>
<pre style="white-space:pre-wrap; word-wrap:break-word;">cloudflare</pre>
<h5>http-trane-info</h5>
<pre style="white-space:pre-wrap; word-wrap:break-word;">Problem with XML parsing of /evox/about</pre>
</td></tr>
<tr class="success">
<td title="Port">8080</td>
Expand Down
8 changes: 4 additions & 4 deletions results/aHR0cHM6Ly9kZWNlcy5tYXRjaGlkLmlv/nmapvuln.nmap
Original file line number Diff line number Diff line change
@@ -1,18 +1,18 @@
# Nmap 7.92 scan initiated Sun Jul 2 01:21:33 2023 as: nmap -sV --script vulners --script-args mincvss=5.0 -oA /data/nmapvuln deces.matchid.io
# Nmap 7.92 scan initiated Sun Jul 9 01:23:36 2023 as: nmap -sV --script vulners --script-args mincvss=5.0 -oA /data/nmapvuln deces.matchid.io
Nmap scan report for deces.matchid.io (104.21.64.91)
Host is up (0.0096s latency).
Host is up (0.0094s latency).
Other addresses for deces.matchid.io (not scanned): 172.67.179.218 2606:4700:3030::6815:405b 2606:4700:3031::ac43:b3da
Not shown: 996 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
80/tcp open http Cloudflare http proxy
|_http-server-header: cloudflare
443/tcp open ssl/http Cloudflare http proxy
|_http-trane-info: Problem with XML parsing of /evox/about
|_http-server-header: cloudflare
|_http-trane-info: Problem with XML parsing of /evox/about
8080/tcp open http Cloudflare http proxy
|_http-server-header: cloudflare
8443/tcp open ssl/http Cloudflare http proxy
|_http-server-header: cloudflare

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Sun Jul 2 01:22:12 2023 -- 1 IP address (1 host up) scanned in 38.96 seconds
# Nmap done at Sun Jul 9 01:24:15 2023 -- 1 IP address (1 host up) scanned in 39.42 seconds
Loading

0 comments on commit 5bdaa77

Please sign in to comment.