Found
Duration
Date
IP
- Nikto --------------------------------------------------------------------------- + Multiple IPs found: 54.214.31.161, 34.217.252.38, 44.226.248.54, 2600:1f14:62a:de84::dd11, 2600:1f14:62a:de83::4823, 2600:1f14:62a:de85::d7d8 + Target IP: 54.214.31.161 + Target Hostname: help.netflix.com + Target Port: 80 + Start Time: 2025-01-31 06:18:13 (GMT-8) --------------------------------------------------------------------------- + Server: No banner retrieved + /: Retrieved via header: 1.1 i-0b15a732267418522 (us-west-2). + /: Uncommon header 'x-originating-url' found, with contents: http://help.netflix.com/. + /: Uncommon header 'x-netflix.nfstatus' found, with contents: 1_21. + /: Uncommon header 'x-netflix.proxy.execution-time' found, with contents: 2. + /: Cookie nfvdid created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies + Root page / redirects to: https://help.netflix.com/ + No CGI Directories found (use '-C all' to force check all possible dirs) + /clientaccesspolicy.xml: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/missing-content-type-header/ + /clientaccesspolicy.xml contains 40 lines which should be manually viewed for improper domains or wildcards. See: https://www.acunetix.com/vulnerabilities/web/insecure-clientaccesspolicy-xml-file/ + /crossdomain.xml contains 1 line which include the following domains: *.netflix.com . See: http://jeremiahgrossman.blogspot.com/2008/05/crossdomainxml-invites-cross-site.html + OPTIONS: Allowed HTTP Methods: GET, HEAD, POST, PUT, DELETE, TRACE, OPTIONS, SCRIPT . + HTTP method ('Allow' Header): 'PUT' method could allow clients to save files on the web server. + HTTP method ('Allow' Header): 'DELETE' may allow clients to remove files on the web server. + Scan terminated: 20 error(s) and 11 item(s) reported on remote host + End Time: 2025-01-31 06:18:53 (GMT-8) (40 seconds) --------------------------------------------------------------------------- + 1 host(s) tested