- Nikto --------------------------------------------------------------------------- + Multiple IPs found: 52.84.20.67, 52.84.20.2, 52.84.20.24, 52.84.20.46, 2600:9000:203a:c000:5:e4ca:5b80:93a1, 2600:9000:203a:400:5:e4ca:5b80:93a1, 2600:9000:203a:a000:5:e4ca:5b80:93a1, 2600:9000:203a:d800:5:e4ca:5b80:93a1, 2600:9000:203a:8600:5:e4ca:5b80:93a1, 2600:9000:203a:6200:5:e4ca:5b80:93a1, 2600:9000:203a:3200:5:e4ca:5b80:93a1, 2600:9000:203a:6600:5:e4ca:5b80:93a1 + Target IP: 52.84.20.67 + Target Hostname: www.americanas.com.br + Target Port: 80 + Start Time: 2025-12-01 04:32:12 (GMT-8) --------------------------------------------------------------------------- + Server: CloudFront + /: Retrieved via header: 1.1 ae33f629b316ed04089a480fd5bcedd2.cloudfront.net (CloudFront). + Root page / redirects to: https://www.americanas.com.br/ + No CGI Directories found (use '-C all' to force check all possible dirs) + : Server banner changed from 'CloudFront' to 'Kestrel'. + /.well-known/assetlinks.json: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/missing-content-type-header/ + /.well-known/assetlinks.json: Google Asset Links Specification file may contain server info. See: RFC-5785 https://github.com/google/digitalassetlinks/blob/master/well-known/details.md + /.well-known/apple-app-site-association: Apple Universal Links. + /.well-known/assetlinks.json: Android App Links. + 8157 requests: 0 error(s) and 6 item(s) reported on remote host + End Time: 2025-12-01 04:32:37 (GMT-8) (25 seconds) --------------------------------------------------------------------------- + 1 host(s) tested