- Nikto v2.6.0 --------------------------------------------------------------------------- + Target IP: 104.26.12.129 + Target Hostname: saddlebackleather.com + Target Port: 80 + Platform: Unknown + Start Time: 2026-08-31 15:22:01 (GMT-4) --------------------------------------------------------------------------- + Server: cloudflare + Multiple IPs found: 104.26.12.129, 104.26.13.129, 172.67.73.252, 2606:4700:20::ac43:49fc, 2606:4700:20::681a:c81, 2606:4700:20::681a:d81 + [999986] /: Retrieved via header: 1.1 google. + [999100] /: Uncommon header(s) 'x-bc-is-ha' found, with contents: 1. + [999100] /: Uncommon header(s) 'bc-ray' found, with contents: 1,1. + [999100] /: Uncommon header(s) 'x-bc-store-id' found, with contents: 1000984217. + [999100] /: Uncommon header(s) 'x-request-id' found, with contents: 58b6adc003a53c3dc7ec6f15ed6d12bc. + [999100] /: Uncommon header(s) 'x-makeswift-page-locale' found, with contents: en. + [011799] /: An alt-svc header was found which is advertising HTTP/3. The endpoint is: ':443'. Nikto cannot test HTTP/3 over QUIC. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/alt-svc + [999106] /: Cloudflare detected via cf-ray header. Recommend proxying via Burp or mitmproxy to avoid TLS fingerprint blocks. See: https://github.com/sullo/nikto/wiki/Using-a-Proxy + [013587] /: Suggested security header missing: referrer-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy + [013587] /: Suggested security header missing: content-security-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP + [013587] /: Suggested security header missing: permissions-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Permissions-Policy + [999100] /index.html: Uncommon header(s) 'reporting-endpoints' found, with contents: cf-csp-endpoint="https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=zY23GxAWVE4xs3AWhwzsJPPiKfZLrp6py2XqvF1Ihn4-1788204126.4082139-1.0.1.1-kcdUbOk64VxPbwmq4nlTDX3vgxNjQfwIbw34fYBOxC2gs_tQYNv0ipyb4kUcHbpjxnMDMIm20swF5cPt7E6EqgMpMYyiiLf7IaB.VkkG72fceMxiKkikoXRIWoYw71P0mpDZMsdK.ynEJpoFd8iWqCeDB6rLLzfECr4BP4RJSP_QGkULX4ApSObl92wKGAl7". + [95] /nikto-test-5JTqG5h8.html: Cookie SF-CSRF-TOKEN created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + [95] /nikto-test-5JTqG5h8.html: Cookie fornax_anonymousId created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + [95] /nikto-test-5JTqG5h8.html: Cookie XSRF-TOKEN created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + [000427] /nikto-test-5JTqG5h8.html: Link header(s) found with value(s): ; rel=preload; as=script, ; rel=preload; as=script, ; rel=preload; as=script, ; rel=preload; as=script, ; rel=preconnect; as=font; crossorigin=anonymous, ; rel=preconnect; as=font; crossorigin=anonymous, ; rel=preconnect; as=font; crossorigin=anonymous, ; rel=preload; as=style, ; rel=preload; as=style, ; rel=preload; as=style, ; rel=preload; as=style, ; rel=preload; as=style, ; rel=preload; as=style. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Link + [800264] /: cloudflare - Cloudflare detected via banner. Recommend proxying via Burp or mitmproxy to avoid TLS fingerprint blocks if not already proxying. + Scan terminated: 0 errors and 17 items reported on the remote host + End Time: 2026-08-31 15:23:02 (GMT-4) (61 seconds) --------------------------------------------------------------------------- + 1 host(s) tested