Scan report for "customerevents.netflix.com"

Membership level: Free member
Summary

Found

16

Duration

1min 11sec

Date

2025-11-21

IP

44.205.57.37

Report
Nikto scan (max 60 sec) (nikto -host customerevents.netflix.com -maxtime 60)
- Nikto 
---------------------------------------------------------------------------
+ Multiple IPs found: 44.205.57.37, 3.230.56.88, 54.175.114.128, 2600:1f18:631e:2f80::21a4, 2600:1f18:631e:2f85::7e01, 2600:1f18:631e:2f84::ac8d
+ Target IP:          44.205.57.37
+ Target Hostname:    customerevents.netflix.com
+ Target Port:        80
+ Start Time:         2025-11-20 22:46:24 (GMT-8)
---------------------------------------------------------------------------
+ Server: envoy
+ /: Retrieved via header: 1.1 i-0dd747cc87f85014a (us-east-1).
+ /: Retrieved access-control-allow-origin header: http://customerevents.netflix.com:7004.
+ /: Uncommon header 'x-netflix.nfstatus' found, with contents: 1_1.
+ /: Uncommon header 'x-originating-url' found, with contents: http://customerevents.netflix.com/.
+ /: Uncommon header 'x-netflix-headerandmsl.profileguid.match' found, with contents: NA.
+ /: Uncommon header 'x-netflix-cookieandmsl.profileguid.match' found, with contents: NA.
+ /: Uncommon header 'x-envoy-decorator-operation' found, with contents: lo_svc_http.
+ /: Uncommon header 'x-envoy-upstream-service-time' found, with contents: 0.
+ /: Uncommon header 'x-b3-traceid' found, with contents: 69200ac03857a0d00c9fb4eca19faa0c.
+ /: Uncommon header 'x-request-id' found, with contents: 46af029e-ca68-4147-bf20-d9a59014d856.
+ /: Uncommon header 'x-netflix-headerandcookie.profileguid.match' found, with contents: NA.
+ /: Uncommon header 'x-netflix.proxy.execution-time' found, with contents: 3.
+ All CGI directories 'found', use '-C none' to test none
+ /clientaccesspolicy.xml: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/missing-content-type-header/
+ /clientaccesspolicy.xml contains 40 lines which should be manually viewed for improper domains or wildcards. See: https://www.acunetix.com/vulnerabilities/web/insecure-clientaccesspolicy-xml-file/
+ /crossdomain.xml contains 1 line which include the following domains: *.netflix.com . See: http://jeremiahgrossman.blogspot.com/2008/05/crossdomainxml-invites-cross-site.html
+ /com.jks: Cookie nfvdid created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies
+ Scan terminated: 1 error(s) and 16 item(s) reported on remote host
+ End Time:           2025-11-20 22:47:35 (GMT-8) (71 seconds)
---------------------------------------------------------------------------
+ 1 host(s) tested
Detailed report
Target
customerevents.netflix.com
Target IP
44.205.57.37
Scan method
Nikto scan (max 60 sec)
Run command
nikto -host customerevents.netflix.com -maxtime 60
Duration
Quick report
Scan date
21 Nov 2025 01:47
Copy scan report
Download report
Remove scan result
$
Check ports
API - Scan ID