25
低风险
2026-05-21 04:10:47
发现的安全问题
- ⚠️[LOW] 服务器信息泄露
- ⚠️[MEDIUM] 缺少 HTTP 安全头
修复建议
- 💡添加 DMARC 记录增强邮件安全
- 💡配置 Web 服务器添加这些安全头
- 💡移除或修改 Server/X-Powered-By 响应头
🌐域名信息
目标域名york.ac.uk
注册域名york.ac.uk
顶级域名.ac.uk
🛡️威胁情报 (7 platforms)
Blacklist未列入黑名单
Malware0
Phishing0
Abuse Score0/100
🐛发现的漏洞 (2)
MEDIUM缺少 HTTP 安全头
缺少以下安全头: X-XSS-Protection, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
修复建议: 配置 Web 服务器添加这些安全头
LOW服务器信息泄露
响应头泄露服务器信息: Server: cloudflare
修复建议: 移除或修改 Server/X-Powered-By 响应头
🔌开放端口 (2)
80
http
443
https
🌐DNS 记录
A: 144.32.128.115
AAAA: 2001:630:61:180::1:73
MX: 10 alt3.aspmx.l.google.com.
MX: 1 aspmx.l.google.com.
MX: 5 alt2.aspmx.l.google.com.
MX: 10 alt4.aspmx.l.google.com.
MX: 5 alt1.aspmx.l.google.com.
NS: ns1.york.ac.uk.
NS: ns2.york.ac.uk.
NS: ns0.york.ac.uk.
NS: auth1.dns.cam.ac.uk.
TXT: "twilio-domain-verification=1395e7d15ae1fac1a10b8a7b0ad5e66e"
TXT: "mandrill_verify.3Ru1mvZzZJy5d2dGlzkKaQ"
TXT: "formstack-domain-verification=8f07a12621b9628970ca76f97743e294"
TXT: "atlassian-domain-verification=Yhq9OnKNxMwugKi1gcSWjAn1xqUW9Ig4EjWsmd0f/xoTFwDaWmLoQpZ3Z0YKi1zw"
TXT: "docusign=15f9236f-fcc7-43a8-b92d-a7f61feaf46b"
TXT: "9j7dn62br4c9bj3rc1ug6mal1q"
TXT: "v=spf1 include:_spf.york.ac.uk include:_spf.google.com -all"
SOA: nse0m.york.ac.uk. hostmaster.york.ac.uk. 2018182691 28800 7200 1209600 86400
📋HTTP 响应头
X-Frame-Options: DENY
Strict-Transport-Security: max-age=15768000
Content-Security-Policy: upgrade-insecure-requests
Server: cloudflare