- Nikto --------------------------------------------------------------------------- + Multiple IPs found: 104.26.9.236, 172.67.71.116, 104.26.8.236, 2606:4700:20::681a:9ec, 2606:4700:20::ac43:4774, 2606:4700:20::681a:8ec + Target IP: 104.26.9.236 + Target Hostname: bloxluck.com + Target Port: 80 + Start Time: 2025-11-04 08:10:49 (GMT-8) --------------------------------------------------------------------------- + Server: cloudflare + /: Retrieved access-control-allow-origin header: *. + /: An alt-svc header was found which is advertising HTTP/3. The endpoint is: ':443'. Nikto cannot test HTTP/3 over QUIC. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/alt-svc + Root page / redirects to: https://bloxluck.com/ + /opOW57Ew.TPF: Uncommon header 'server-timing' found, with contents: cfL4;desc="?proto=TCP&rtt=1593&min_rtt=841&rtt_var=1611&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2915&recv_bytes=776&delivery_rate=1662456&cwnd=253&unsent_bytes=0&cid=0000000000000000&ts=0&x=0". + All CGI directories 'found', use '-C none' to test none + /: Uncommon header 'proxy-status' found, with contents: Cloudflare-Proxy;error=http_request_error. + /cgi-915/cart.pl?db=': IP address found in the 'content-security-policy-report-only' header. The IP is "1.0.1.1". See: https://portswigger.net/kb/issues/00600300_private-ip-addresses-disclosed + Scan terminated: 0 error(s) and 5 item(s) reported on remote host + End Time: 2025-11-04 08:11:50 (GMT-8) (61 seconds) --------------------------------------------------------------------------- + 1 host(s) tested