- Nikto v2.6.0 --------------------------------------------------------------------------- + Target IP: 142.250.31.190 + Target Hostname: youtube.com + Target Port: 80 + Platform: Unknown + Start Time: 2026-07-03 15:29:14 (GMT-4) --------------------------------------------------------------------------- + Server: ESF + Multiple IPs found: 142.250.31.190, 142.250.31.136, 142.250.31.93, 142.250.31.91, 2607:f8b0:4004:c0b::5b, 2607:f8b0:4004:c0b::5d, 2607:f8b0:4004:c0b::88, 2607:f8b0:4004:c0b::be + No CGI Directories found (use '-C all' to force check all possible dirs). CGI tests skipped. + [999962] /: Server banner changed from 'ESF' to 'sffe'. + [95] /: Cookie __Secure-STRP created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + [000427] /: Link header(s) found with value(s): ; rel="compression-dictionary". See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Link + [013587] /: Suggested security header missing: referrer-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy + [013587] /: Suggested security header missing: strict-transport-security. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security + [013587] /: Suggested security header missing: permissions-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Permissions-Policy + [013587] /: Suggested security header missing: content-security-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP + Scan terminated: 0 errors and 7 items reported on the remote host + End Time: 2026-07-03 15:30:15 (GMT-4) (61 seconds) --------------------------------------------------------------------------- + 1 host(s) tested