25
低风险
2026-05-21 04:58:50
发现的安全问题
- ⚠️[LOW] 服务器信息泄露
- ⚠️[MEDIUM] 缺少 HTTP 安全头
修复建议
- 💡添加 DMARC 记录增强邮件安全
- 💡配置 Web 服务器添加这些安全头
- 💡移除或修改 Server/X-Powered-By 响应头
🌐域名信息
目标域名lufthansa.com
注册域名lufthansa.com
顶级域名.com
🛡️威胁情报 (7 platforms)
Blacklist未列入黑名单
Malware0
Phishing0
Abuse Score0/100
🐛发现的漏洞 (2)
MEDIUM缺少 HTTP 安全头
缺少以下安全头: Content-Security-Policy, Permissions-Policy
修复建议: 配置 Web 服务器添加这些安全头
LOW服务器信息泄露
响应头泄露服务器信息: Server: cloudflare
修复建议: 移除或修改 Server/X-Powered-By 响应头
🔌开放端口 (2)
80
http
443
https
🌐DNS 记录
A: 20.101.251.232
MX: 10 mxa-005f4701.gslb.pphosted.com.
MX: 10 mxb-005f4701.gslb.pphosted.com.
NS: udns1.cscudns.com.
NS: udns2.cscudns.org.
TXT: " ir0llfualq0lc0rrpus8hckeir"
TXT: "apple-domain-verification=dgPxFEVd2K3xQqtz"
TXT: "_3lqbnk5ht5r15umni1kxyppvmdy3y1c"
TXT: "cloudpiercer-verification=dc4279b6fad885058db091939393c054"
TXT: "cloudControl-verification: f6b65ab213e089875abd83bd4220d316ad10b16e4e64e2ccabef24e86eb3b563"
TXT: "facebook-domain-verification=jr9ai9g9jfp6b646oq7kay8xw4edgp"
TXT: "MS=ms85757355"
TXT: "docusign=8bea4f11-e5ab-4856-99e4-4ca3d798adaf"
TXT: "qucYgggiw9JwlYkwN1eWMmo+t5nlajTRSugGKykCY1g0BBFD5fa+U3YYCGL2jDR0c4T1gQD02IZyJsUEYMmTkA=="
TXT: "v=spf1 mx ip4:129.35.195.69 ip4:129.35.195.68 ip4:129.35.195.132 ip4:129.35.195.133 ip4:84.17.165.165 ip4:84.17.165.167 ip4:194.31.6.64/28 ip4:52.157.235.82 ip4:80.72.142.246 ip4:80.77.215.176/28 ip4:84.17.184.240/28 ip4:84.17.190.192/26" " include:spf.ecentry.io include:amazonses.com include:_relay.amadeus.com include:_spf.lufthansa.com -all"
TXT: "_rd9relssqtk8z4vl6yn9hk66l4fc8zd"
TXT: "google-site-verification=F9d17-cGR9pWXhdWBAAoVSCULdLFHg581R98t75oZ9M"
TXT: "google-site-verification=A1d4RptY5Tgo2iMXRQUdNN1YDiCDRF9qi8rogpch4hQ"
TXT: "_globalsign-domain-verification=VzENNhYl3dL1bbkkax4Zn0AKFBSeyIt9K3GSm43box"
TXT: "1qbYXTIQfi1P3mqgJMun2NUm9qbzeAmMCvRn0q+p3wNof6cn0F3+vN3JHmLIkyAuA8yz1ya0IKosGsOs8Npt/Q=="
TXT: "_atv5tb360u8dld1ndsus1qfru3cf6pt"
SOA: udns1.cscudns.com. hostmaster.cscdns.net. 2019107360 28800 7200 1209600 86400
📋HTTP 响应头
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=15768000
Referrer-Policy: same-origin
Server: cloudflare