52
High Risk
2026-05-21 08:20:55
Security Issues Found
- ⚠️[HIGH] 敏感路径暴露
- ⚠️被列入 1 个黑名单: AlienVault OTX
- ⚠️[MEDIUM] 缺少 HTTP 安全头
- ⚠️AlienVault OTX 有 1 个社区讨论(非直接威胁)
Recommendations
- 💡添加 DMARC 记录增强邮件安全
- 💡配置 Web 服务器添加这些安全头
- 💡申请从黑名单中移除,并修复安全问题
- 💡限制对这些路径的访问或添加认证
🌐Domain Info
Targetbseindia.com
Registeredbseindia.com
TLD.com
🛡️Threat Intelligence (7 platforms)
BlacklistAlienVault OTX
Malware1
Phishing0
Abuse Score0/100
🐛Vulnerabilities Found (2)
MEDIUM缺少 HTTP 安全头
缺少以下安全头: Permissions-Policy
Fix: 配置 Web 服务器添加这些安全头
HIGH敏感路径暴露
发现可访问的敏感路径: /.env
Fix: 限制对这些路径的访问或添加认证
🔌Open Ports (2)
80
http
443
https
🌐DNS Records
A: 23.35.148.138
A: 23.35.148.169
AAAA: 2600:1417:4400:7::1720:3d98
AAAA: 2600:1417:4400:7::1720:3dad
MX: 1 bseindia-com.mail.protection.outlook.com.
NS: a3-66.akam.net.
NS: a4-65.akam.net.
NS: a1-223.akam.net.
NS: a7-64.akam.net.
NS: a20-67.akam.net.
NS: a14-66.akam.net.
TXT: "fwVQvy1sI3SHY6xfIatxYcV+tJCQJkqR8mOE7OmRKfc="
TXT: "_globalsign-domain-verification=euqYa76dfeM-HdGyogleMhBfQTPCKcPTOVWrFwgRe7"
TXT: "google-site-verification=KcTC1oQHgmtHGe2e7YSNuEgNyjioVxpW0yPpwo-KgTI"
TXT: "MS=ms34510036"
TXT: "onwXPDZexnOa7yxe14TE+Nw6/pRRpWTHs0G7FcXjPGc="
TXT: "e2c215a682a60c5c766b08d9374f045f"
TXT: "cisco-ci-domain-verification=11e68431c44477ac462697ca2c56e1e7b49b8ed3d49999a7c1508f9ca394247e"
TXT: "dxpbOw4Fq9db78Ub+v+xUKJI+BFZBI/gCiI+b2pRzMo="
TXT: "v=spf1 include:zsend.in include:spf.protection.outlook.com include:ncapp02.com ip4:203.199.49.0/25 ip4:103.47.198.0/28 ip4:43.228.178.0/26 ip4:35.154.253.137/32 ip4:13.201.153.112/32 ip4:13.205.182.216/32 include:smtprelay.bseindia.com -all"
TXT: "7ydbJZTRlTj6TiA6PF8tUk70MHvWpZN+cIDCc9bt+kJsHH7WEwpyO9cXmV+qCt3UvrYzzHCp2R+LZBhkeTTvNQ=="
TXT: "globalsign-domain-verification=RG9AYTEO0o3zvpoRTELdKWHIQBb5i7Q_7_B2JyjlkQ"
SOA: a1-223.akam.net. hostmaster.bseindia.com. 2020063485 900 600 86400 3600
📋HTTP Headers
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Content-Security-Policy: default-src https://*.googlesyndication.com 'self'; img-src *.gstatic.com *.google.com 'self' data: chrome-extension-
Referrer-Policy: same-origin | strict-origin-when-cross-origin