- Nikto --------------------------------------------------------------------------- + Multiple IPs found: 23.227.38.74, 2620:127:f00f:e:: + Target IP: 23.227.38.74 + Target Hostname: shop.carnegiehall.org + Target Port: 80 + Start Time: 2024-08-28 16:15:08 (GMT-4) --------------------------------------------------------------------------- + Server: cloudflare + /: Cookie localization created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + /: Cookie cart_currency created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + /: Cookie _tracking_consent created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + /: Cookie _cmp_a created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + /: Cookie _shopify_y created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + /: Cookie _shopify_s created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + /: Retrieved powered-by header: Shopify. + /:X-Frame-Options header is deprecated and has been replaced with the Content-Security-Policy HTTP header with the frame-ancestors directive instead. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options + /: Link header found with value: ; rel="preconnect", ; rel="preconnect"; crossorigin. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Link + /: Uncommon header 'x-dc' found, with contents: gcp-us-east1,gcp-us-east1,gcp-us-east1. + /: Uncommon header 'x-shopify-nginx-no-cookies' found, with contents: 0. + /: Uncommon header 'x-storefront-renderer-rendered' found, with contents: 1. + /: Uncommon header 'x-sorting-hat-shopid' found, with contents: 27974139964. + /: Uncommon header 'powered-by' found, with contents: Shopify. + /: Uncommon header 'x-sorting-hat-podid' found, with contents: 169. + /: Uncommon header 'x-shopid' found, with contents: 27974139964. + /: Uncommon header 'server-timing' found, with multiple values: (processing;dur=19;desc="gc:1", db;dur=4, asn;desc="63018", edge;desc="EWR", country;desc="US", theme;desc="133945884842", pageType;desc="index", servedBy;desc="sjn4", requestID;desc="db178ca7-775f-4507-8ae6-eae6a5330ef9-1724876108",cfRequestDuration;dur=67.999840,). + /: Uncommon header 'x-shardid' found, with contents: 169. + /: Uncommon header 'x-request-id' found, with contents: db178ca7-775f-4507-8ae6-eae6a5330ef9-1724876108. + /: An alt-svc header was found which is advertising HTTP/3. The endpoint is: ':443'. Nikto cannot test HTTP/3 over QUIC. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/alt-svc + No CGI Directories found (use '-C all' to force check all possible dirs) + /27974139964/orders/: Uncommon header 'x-liquid-rendered-at' found, with contents: 2024-08-28T20:15:40.733777016Z. + /apple-app-site-association/: Uncommon header 'content-disposition' found, with contents: attachment; filename=apple-app-site-association. + /apple-app-site-association/: Uncommon header 'content-transfer-encoding' found, with contents: binary. + /robots.txt: Entry '/apple-app-site-association/' is returned a non-forbidden or redirect HTTP code (200). See: https://portswigger.net/kb/issues/00600600_robots-txt-file + /checkout/: Cookie cart created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + /robots.txt: contains 128 entries which should be manually viewed. See: https://developer.mozilla.org/en-US/docs/Glossary/Robots.txt + Multiple index files found: /index.jsp, /index.xml, /index.cfm, /index.php4, /index.php5, /index.aspx, /index.jhtml, /index.htm, /index.php7, /index.shtml, /index.pl, /index.php, /index.do, /index.asp, /index.php3, /index.cgi, /index.html. + Scan terminated: 0 error(s) and 27 item(s) reported on remote host + End Time: 2024-08-28 16:16:09 (GMT-4) (61 seconds) --------------------------------------------------------------------------- + 1 host(s) tested