- Nikto v2.6.0 --------------------------------------------------------------------------- + Target IP: 172.67.73.252 + Target Hostname: saddlebackleather.com + Target Port: 80 + Platform: Linux/Unix + Start Time: 2026-08-31 15:03:45 (GMT-4) --------------------------------------------------------------------------- + Server: cloudflare + Multiple IPs found: 172.67.73.252, 104.26.13.129, 104.26.12.129, 2606:4700:20::681a:c81, 2606:4700:20::ac43:49fc, 2606:4700:20::681a:d81 + [999986] /: Retrieved via header: 1.1 google. + [999100] /: Uncommon header(s) 'x-bc-is-ha' found, with contents: 1. + [999100] /: Uncommon header(s) 'x-request-id' found, with contents: 3a15d51b78c1eba8aac746aefba55cd7. + [999100] /: Uncommon header(s) 'x-bc-store-id' found, with contents: 1000984217. + [999100] /: Uncommon header(s) 'bc-ray' found, with contents: 1,1. + [999100] /: Uncommon header(s) 'x-makeswift-page-locale' found, with contents: en. + [011799] /: An alt-svc header was found which is advertising HTTP/3. The endpoint is: ':443'. Nikto cannot test HTTP/3 over QUIC. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/alt-svc + [999106] /: Cloudflare detected via cf-ray header. Recommend proxying via Burp or mitmproxy to avoid TLS fingerprint blocks. See: https://github.com/sullo/nikto/wiki/Using-a-Proxy + [013587] /: Suggested security header missing: referrer-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy + [013587] /: Suggested security header missing: content-security-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP + [013587] /: Suggested security header missing: permissions-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Permissions-Policy + [95] /nikto-test-kmpwt7Kn.html: Cookie SF-CSRF-TOKEN created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + [95] /nikto-test-kmpwt7Kn.html: Cookie fornax_anonymousId created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + [95] /nikto-test-kmpwt7Kn.html: Cookie XSRF-TOKEN created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + [000427] /nikto-test-kmpwt7Kn.html: Link header(s) found with value(s): ; rel=preload; as=script, ; rel=preload; as=script, ; rel=preload; as=script, ; rel=preload; as=script, ; rel=preconnect; as=font; crossorigin=anonymous, ; rel=preconnect; as=font; crossorigin=anonymous, ; rel=preconnect; as=font; crossorigin=anonymous, ; rel=preload; as=style, ; rel=preload; as=style, ; rel=preload; as=style, ; rel=preload; as=style, ; rel=preload; as=style, ; rel=preload; as=style. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Link + [999100] /dump.jks: Uncommon header(s) 'reporting-endpoints' found, with contents: cf-csp-endpoint="https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=KcBSJRbMrQbvA0FYSgdPmY81XjrOdpaiN3Ygajw_lz0-1788203043.1967556-1.0.1.1-aHBzqYzO6yvJSk5IsTuePEgMDEYVoYuCWryz190RSm4NmDsLN2vg_hhVt5Ip7oiebzfQldEd7cvnA4jO5h46EW1uDzm68RLH1Lzkl7xZTq3D6CSBBTxv0m5e7UCx1yFujCHvLEfvNPuks9me0gXzdYYD2n4ZyYBX7D6SdFOQJyv_v1A7ptz4oQ3ilRnnIn3v". + [800264] /: cloudflare - Cloudflare detected via banner. Recommend proxying via Burp or mitmproxy to avoid TLS fingerprint blocks if not already proxying. + Scan terminated: 0 errors and 17 items reported on the remote host + End Time: 2026-08-31 15:04:46 (GMT-4) (61 seconds) --------------------------------------------------------------------------- + 1 host(s) tested