- Nikto v2.6.0 --------------------------------------------------------------------------- + Target IP: 3.219.126.241 + Target Hostname: smugmug.com + Target Port: 80 + Platform: Unknown + Start Time: 2026-05-14 11:50:49 (GMT-4) --------------------------------------------------------------------------- + Server: nginx + Multiple IPs found: 3.219.126.241, 18.214.125.52, 34.192.200.176 + [999100] /: Uncommon header(s) 'x-s' found, with contents: 100.2.247:1609692. + [999100] /: Uncommon header(s) 'smug-cdn' found, with contents: cloudflare (via smugmug.com). + [999100] /: Uncommon header(s) 'x-ttfb-l' found, with contents: . + [999100] /: Uncommon header(s) 'x-env' found, with contents: a=live, b=www, c=4cf206a9, d=i-063367c292984e6ee. + [999100] /: Uncommon header(s) 'x-ttfb' found, with contents: 0.0088. + [999100] /: Uncommon header(s) 'x-request-id' found, with contents: bf754fa9. + No CGI Directories found (use '-C all' to force check all possible dirs). CGI tests skipped. + [999962] /: Server banner changed from 'nginx' to 'awselb/2.0'. + [013587] /: Suggested security header missing: permissions-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Permissions-Policy + [013587] /: Suggested security header missing: referrer-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy + [013587] /: Suggested security header missing: content-security-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP + [013587] /: Suggested security header missing: x-content-type-options. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options + [999986] http://127.0.0.1:2301/%20HTTP/1.0: Retrieved x-powered-by header: SmugMug/1.0. + [000427] http://127.0.0.1:2301/%20HTTP/1.0: Link header(s) found with value(s): ; rel="preconnect", ; rel="preload"; as="script"; crossorigin, ; rel="preconnect", ; rel="preload"; as="script"; crossorigin, ; rel="preconnect", ; rel="preload"; as="style", ; rel="preconnect", ; rel="preconnect", ; rel="preconnect", ; rel="dns-prefetch", ; rel="preconnect", ; rel="preload"; as="style", ; rel="preconnect", ; rel="preload"; as="style", ; rel="preconnect", ; rel="preload"; as="style", ; rel="preconnect", ; rel="preload"; as="script"; crossorigin. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Link + [999100] http://127.0.0.1:2301/%20HTTP/1.0: Uncommon header(s) 'x-smugmug-values' found, with contents: 3/5 - Deliver Awesome. + [999100] http://127.0.0.1:2301/%20HTTP/1.0: Uncommon header(s) 'x-smugmug-hiring' found, with contents: How to love what you do: https://jobs.smugmug.com/. + Scan terminated: 0 errors and 15 items reported on the remote host + End Time: 2026-05-14 11:51:50 (GMT-4) (61 seconds) --------------------------------------------------------------------------- + 1 host(s) tested