- Nikto --------------------------------------------------------------------------- + Multiple IPs found: 52.40.3.60, 52.36.99.123 + Target IP: 52.40.3.60 + Target Hostname: gaiaonline.com + Target Port: 80 + Start Time: 2025-10-03 04:20:08 (GMT-7) --------------------------------------------------------------------------- + Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/7.4.19 mod_auth_tkt/2.3.99b1 + /: Retrieved x-powered-by header: PHP/7.4.19. + /: Retrieved access-control-allow-origin header: *. + Root page / redirects to: https://gaiaonline.com/ + /WLzw8SDG.swf: Uncommon header 'x-gaia-404' found, with contents: caching. + /robots.txt: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/missing-content-type-header/ + /robots.txt: Entry '/gaia/members/' is returned a non-forbidden or redirect HTTP code (200). See: https://portswigger.net/kb/issues/00600600_robots-txt-file + /robots.txt: Entry '/chat/' is returned a non-forbidden or redirect HTTP code (200). See: https://portswigger.net/kb/issues/00600600_robots-txt-file + /tank/:X-Frame-Options header is deprecated and has been replaced with the Content-Security-Policy HTTP header with the frame-ancestors directive instead. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options + /robots.txt: Entry '/tank/' is returned a non-forbidden or redirect HTTP code (200). See: https://portswigger.net/kb/issues/00600600_robots-txt-file + /launch/: Cookie testcookie created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + /robots.txt: contains 60 entries which should be manually viewed. See: https://developer.mozilla.org/en-US/docs/Glossary/Robots.txt + /crossdomain.xml contains 5 lines which include the following domains: *.gaiaonline.com" to-ports="80,443,843,5222,8080,9933" secure="false *.cdn.gaiaonline.com" to-ports="80,443,5222,8080,9933" secure="false *.brightcove.com *.edgecastcdn.net" to-ports="80,443" secure="false *.wac.edgecastcdn.net" to-ports="80,443" secure="false . See: http://jeremiahgrossman.blogspot.com/2008/05/crossdomainxml-invites-cross-site.html + : Server banner changed from 'Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/7.4.19 mod_auth_tkt/2.3.99b1' to 'awselb/2.0'. + OpenSSL/1.0.2k-fips appears to be outdated (current is at least 3.2.0). OpenSSL 1.1.1w is current for 1.x and is supported via contract, and 3.0.12 for 3.0.x, and 3.1.4 for 3.1.x. + Apache/2.4.6 appears to be outdated (current is at least 2.4.58). Apache 2.2.34 is the EOL for the 2.x branch. + PHP/7.4.19 appears to be outdated (current is at least 8.3.0). + /index: Uncommon header 'tcn' found, with contents: list. + /index: Apache mod_negotiation is enabled with MultiViews, which allows attackers to easily brute force file names. The following alternatives for 'index' were found: index.html, index.php. See: http://www.wisec.it/sectou.php?id=4698ebdc59d15,https://exchange.xforce.ibmcloud.com/vulnerabilities/8275 + Scan terminated: 0 error(s) and 17 item(s) reported on remote host + End Time: 2025-10-03 04:21:09 (GMT-7) (61 seconds) --------------------------------------------------------------------------- + 1 host(s) tested ********************************************************************* Portions of the server's headers (mod_auth_tkt/2.3.99b1) are not in the Nikto 2.5.0 database or are newer than the known string. Would you like to submit this information (*no server specific data*) to CIRT.net for a Nikto update (or you may email to sullo@cirt.net) (y/n)?