45
Medium Risk
2026-05-21 07:06:26
Security Issues Found
- ⚠️[HIGH] 敏感路径暴露
- ⚠️[MEDIUM] 缺少 HTTP 安全头
Recommendations
- 💡添加 DMARC 记录增强邮件安全
- 💡配置 Web 服务器添加这些安全头
- 💡限制对这些路径的访问或添加认证
🌐Domain Info
Targetnla.gov.au
Registerednla.gov.au
TLD.gov.au
🛡️Threat Intelligence (7 platforms)
BlacklistNot Blacklisted
Malware0
Phishing0
Abuse Score0/100
🐛Vulnerabilities Found (2)
MEDIUM缺少 HTTP 安全头
缺少以下安全头: X-XSS-Protection, Referrer-Policy, Permissions-Policy
Fix: 配置 Web 服务器添加这些安全头
HIGH敏感路径暴露
发现可访问的敏感路径: /.git/config
Fix: 限制对这些路径的访问或添加认证
🔌Open Ports (2)
80
http
443
https
🌐DNS Records
A: 192.102.239.32
MX: 0 nla-gov-au.mail.protection.outlook.com.
NS: ns2.aarnet.net.au.
NS: ns3.aarnet.net.au.
NS: ns1.aarnet.net.au.
NS: smtpgate.nla.gov.au.
NS: ns1.nla.gov.au.
TXT: "v=spf1 include:_spf.createsend.com include:spf.protection.outlook.com include:mailrelay.t1cloud.com ip4:192.102.239.0/24 ip4:203.4.200.9 ip4:202.129.143.17 " "include:outboundmail.blackbaud.net include:spf-ap.exlibrisgroup.com ip6:2603:10c6:220:1b1::12 -all"
TXT: "apple-domain-verification=0lpnzLDj1gf7Xsxi"
TXT: "cZ83yErsg4INnAmVaeD4EwYSrQ+cZLyxiGEEU1Y76wUBk0x+p71Adv24LXYHKfeEETXnWTcskq+ITNUgK+IdPw=="
TXT: "_dddabkl5t0sylvufjl498w3lls5t9qf"
TXT: "Location=P"
TXT: "slack-domain-verification=UnGR4V6jllO74pBcadwm2oo7haHFVPlsot3lpSef"
TXT: "google-site-verification=22n3NusTgBF1Z676SbNeHUhehIUSEsgPRRZfdZsG3_I"
TXT: "google-site-verification=vUrNbcoYJqaSjqeAKxMH75zDD6NVm1Z0FQizHhrZrMk"
TXT: "MS=ms57340175"
TXT: "sophos-domain-verification=d2a36d77c1d75afb3f42a7013fc858588438a5b950682c09b797329896290abd"
TXT: "google-site-verification=vnKBHeOytgo3Kv4BzfGixms733jYyky2rc8C2a4FhXo"
TXT: "ahrefs-site-verification_2aaa26619ccdb102f839b4edfc5657278ab2609a181f083c3277c3e0dd0b847a"
TXT: "atlassian-domain-verification=nmViGVY/tEQ5C6C4/9MRI2zTwUiJbjmXyEjTGXz4GvnupdWiHOWoApaDT8OGwAgw"
TXT: "atlassian-domain-verification=H7TggyJ5c7WygP7T36AZi6VoUrbhT4sHPaj4gnQ0OvBEsDSbDRhU105wp8h2uBMj"
TXT: "google-site-verification=RDVBED6zn0epVQkslGKmy0190K-hW3_AEvCsTLBcSFc"
TXT: "ZOOM_verify_oScA1GtLTYiqqRtsvnJRpw"
SOA: ns1.nla.gov.au. root.ns1.nla.gov.au. 2026051400 10800 3600 604800 3600
📋HTTP Headers
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31557600
Content-Security-Policy: object-src 'none'; script-src * 'report-sample' 'unsafe-inline' 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' *.