════════════════════════════════════════════════════════════════ WEBSEC-AUDIT v1.0.1 — Security Audit Report ════════════════════════════════════════════════════════════════ Target : https://example.com IP : 104.18.27.120 Date : 2026-03-23 16:15:31 Duration : 1541s Auditor : root@debian12 ════════════════════════════════════════════════════════════════ RISK SUMMARY ────────────────────────────────────────────────── CRITICAL 4 HIGH 2 MEDIUM 25 LOW 66 INFO 7 TOTAL 104 ════════════════════════════════════════════════════════════════ FINDINGS ════════════════════════════════════════════════════════════════ [001] [INFO ] [INIT] Audit started against https://example.com Description : Resolved IP: 104.18.27.120 | Mode: NORMAL Timestamp : 2026-03-23T15:15:36Z [002] [INFO ] [RECON] WHOIS data collected for example.com Description : Registrar: N/A | Expiry: 2026-08-13 Timestamp : 2026-03-23T15:15:36Z [003] [INFO ] [RECON] Subdomain enumeration: 37616 hosts discovered Description : 0000.example.com 001.example.com 01.example.com 02.example.com 03.example.com 03----may----rrdd.example.com 04.example.com 05----apr----rrdd.example.com 05.example.com 06----apr----rrdd.example.com Evidence : /root/websec-audit/results_example_com_20260323_161531/recon/subdomains.txt Timestamp : 2026-03-23T15:16:22Z [004] [INFO ] [FINGERPRINT] WAF detected: Cloudflare (Cloudflare Inc.) WAF. Description : The target appears to be protected by a Web Application Firewall. Evidence : Cloudflare (Cloudflare Inc.) WAF. Timestamp : 2026-03-23T15:16:25Z [005] [LOW ] [FINGERPRINT] Version disclosure via 'Server' header Description : The server reveals technology/version info in response headers. Evidence : server: cloudflare Remediation : Remove or neutralise the 'Server' header in your web server configuration. Timestamp : 2026-03-23T15:16:25Z [006] [LOW ] [SSL] testssl: [TLS1] offered (deprecated) Remediation : Refer to testssl documentation for TLS1 Timestamp : 2026-03-23T15:19:44Z [007] [LOW ] [SSL] testssl: [TLS1_1] offered (deprecated) Remediation : Refer to testssl documentation for TLS1_1 Timestamp : 2026-03-23T15:19:44Z [008] [MEDIUM ] [SSL] testssl: [cipherlist_3DES_IDEA] offered Remediation : Refer to testssl documentation for cipherlist_3DES_IDEA Timestamp : 2026-03-23T15:19:44Z [009] [LOW ] [SSL] testssl: [cipherlist_OBSOLETED] offered Remediation : Refer to testssl documentation for cipherlist_OBSOLETED Timestamp : 2026-03-23T15:19:44Z [010] [LOW ] [SSL] testssl: [cipher-tls1_xc013] TLSv1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_xc013 Timestamp : 2026-03-23T15:19:44Z [011] [LOW ] [SSL] testssl: [cipher-tls1_x2f] TLSv1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_x2f Timestamp : 2026-03-23T15:19:44Z [012] [LOW ] [SSL] testssl: [cipher-tls1_xc014] TLSv1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_xc014 Timestamp : 2026-03-23T15:19:44Z [013] [LOW ] [SSL] testssl: [cipher-tls1_x35] TLSv1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_x35 Timestamp : 2026-03-23T15:19:44Z [014] [MEDIUM ] [SSL] testssl: [cipher-tls1_x0a] TLSv1 x0a DES-CBC3-SHA RSA 3DES 168 TLS_RSA_WITH_3DES_EDE_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_x0a Timestamp : 2026-03-23T15:19:44Z [015] [LOW ] [SSL] testssl: [cipher-tls1_1_xc013] TLSv1.1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_1_xc013 Timestamp : 2026-03-23T15:19:44Z [016] [LOW ] [SSL] testssl: [cipher-tls1_1_x2f] TLSv1.1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_1_x2f Timestamp : 2026-03-23T15:19:44Z [017] [LOW ] [SSL] testssl: [cipher-tls1_1_xc014] TLSv1.1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_1_xc014 Timestamp : 2026-03-23T15:19:44Z [018] [LOW ] [SSL] testssl: [cipher-tls1_1_x35] TLSv1.1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_1_x35 Timestamp : 2026-03-23T15:19:44Z [019] [LOW ] [SSL] testssl: [cipher-tls1_2_xc009] TLSv1.2 xc009 ECDHE-ECDSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_xc009 Timestamp : 2026-03-23T15:19:44Z [020] [LOW ] [SSL] testssl: [cipher-tls1_2_xc00a] TLSv1.2 xc00a ECDHE-ECDSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_xc00a Timestamp : 2026-03-23T15:19:44Z [021] [LOW ] [SSL] testssl: [cipher-tls1_2_xc023] TLSv1.2 xc023 ECDHE-ECDSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_xc023 Timestamp : 2026-03-23T15:19:44Z [022] [LOW ] [SSL] testssl: [cipher-tls1_2_xc024] TLSv1.2 xc024 ECDHE-ECDSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_xc024 Timestamp : 2026-03-23T15:19:44Z [023] [LOW ] [SSL] testssl: [cipher-tls1_2_xc013] TLSv1.2 xc013 ECDHE-RSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_xc013 Timestamp : 2026-03-23T15:19:45Z [024] [LOW ] [SSL] testssl: [cipher-tls1_2_x2f] TLSv1.2 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_x2f Timestamp : 2026-03-23T15:19:45Z [025] [LOW ] [SSL] testssl: [cipher-tls1_2_xc014] TLSv1.2 xc014 ECDHE-RSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_xc014 Timestamp : 2026-03-23T15:19:45Z [026] [LOW ] [SSL] testssl: [cipher-tls1_2_x35] TLSv1.2 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_x35 Timestamp : 2026-03-23T15:19:45Z [027] [LOW ] [SSL] testssl: [cipher-tls1_2_xc027] TLSv1.2 xc027 ECDHE-RSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA25 Remediation : Refer to testssl documentation for cipher-tls1_2_xc027 Timestamp : 2026-03-23T15:19:45Z [028] [LOW ] [SSL] testssl: [cipher-tls1_2_x3c] TLSv1.2 x3c AES128-SHA256 RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA256 Remediation : Refer to testssl documentation for cipher-tls1_2_x3c Timestamp : 2026-03-23T15:19:45Z [029] [LOW ] [SSL] testssl: [cipher-tls1_2_xc028] TLSv1.2 xc028 ECDHE-RSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA38 Remediation : Refer to testssl documentation for cipher-tls1_2_xc028 Timestamp : 2026-03-23T15:19:45Z [030] [LOW ] [SSL] testssl: [cipher-tls1_2_x3d] TLSv1.2 x3d AES256-SHA256 RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA256 Remediation : Refer to testssl documentation for cipher-tls1_2_x3d Timestamp : 2026-03-23T15:19:45Z [031] [HIGH ] [SSL] testssl: [cert_keyUsage ] Certificate incorrectly used for key encipherment: 'Digital Signature' Remediation : Refer to testssl documentation for cert_keyUsage Timestamp : 2026-03-23T15:19:45Z [032] [CRITICAL] [SSL] testssl: [cert_chain_of_trust ] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple Remediation : Refer to testssl documentation for cert_chain_of_trust Timestamp : 2026-03-23T15:19:45Z [033] [MEDIUM ] [SSL] testssl: [cert_expirationStatus ] expires < 60 days (52) Remediation : Refer to testssl documentation for cert_expirationStatus Timestamp : 2026-03-23T15:19:45Z [034] [MEDIUM ] [SSL] testssl: [cert_notAfter ] 2026-05-14 18:57 Remediation : Refer to testssl documentation for cert_notAfter Timestamp : 2026-03-23T15:19:45Z [035] [LOW ] [SSL] testssl: [DNS_CAArecord ] -- Remediation : Refer to testssl documentation for DNS_CAArecord Timestamp : 2026-03-23T15:19:45Z [036] [CRITICAL] [SSL] testssl: [cert_chain_of_trust ] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple Remediation : Refer to testssl documentation for cert_chain_of_trust Timestamp : 2026-03-23T15:19:45Z [037] [MEDIUM ] [SSL] testssl: [cert_expirationStatus ] expires < 60 days (52) Remediation : Refer to testssl documentation for cert_expirationStatus Timestamp : 2026-03-23T15:19:45Z [038] [MEDIUM ] [SSL] testssl: [cert_notAfter ] 2026-05-14 18:57 Remediation : Refer to testssl documentation for cert_notAfter Timestamp : 2026-03-23T15:19:45Z [039] [LOW ] [SSL] testssl: [DNS_CAArecord ] -- Remediation : Refer to testssl documentation for DNS_CAArecord Timestamp : 2026-03-23T15:19:45Z [040] [LOW ] [SSL] testssl: [HSTS] not offered Remediation : Refer to testssl documentation for HSTS Timestamp : 2026-03-23T15:19:46Z [041] [MEDIUM ] [SSL] testssl: [security_headers] -- Remediation : Refer to testssl documentation for security_headers Timestamp : 2026-03-23T15:19:46Z [042] [MEDIUM ] [SSL] testssl: [BREACH] potentially VULNERABLE, gzip HTTP compression detected - only supplied '/' tested Remediation : Refer to testssl documentation for BREACH Timestamp : 2026-03-23T15:19:46Z [043] [LOW ] [SSL] testssl: [SWEET32] uses 64 bit block ciphers Remediation : Refer to testssl documentation for SWEET32 Timestamp : 2026-03-23T15:19:46Z [044] [MEDIUM ] [SSL] testssl: [BEAST_CBC_TLS1] ECDHE-RSA-AES128-SHA AES128-SHA ECDHE-RSA-AES256-SHA AES256-SHA DES-CBC3-SHA Remediation : Refer to testssl documentation for BEAST_CBC_TLS1 Timestamp : 2026-03-23T15:19:46Z [045] [LOW ] [SSL] testssl: [BEAST] VULNERABLE -- but also supports higher protocols TLSv1.1 TLSv1.2 (likely mitigated) Remediation : Refer to testssl documentation for BEAST Timestamp : 2026-03-23T15:19:46Z [046] [LOW ] [SSL] testssl: [LUCKY13] potentially vulnerable, uses TLS CBC ciphers Remediation : Refer to testssl documentation for LUCKY13 Timestamp : 2026-03-23T15:19:46Z [047] [MEDIUM ] [SSL] testssl: [overall_grade] B Remediation : Refer to testssl documentation for overall_grade Timestamp : 2026-03-23T15:19:46Z [048] [LOW ] [SSL] testssl: [TLS1] offered (deprecated) Remediation : Refer to testssl documentation for TLS1 Timestamp : 2026-03-23T15:19:46Z [049] [LOW ] [SSL] testssl: [TLS1_1] offered (deprecated) Remediation : Refer to testssl documentation for TLS1_1 Timestamp : 2026-03-23T15:19:46Z [050] [MEDIUM ] [SSL] testssl: [cipherlist_3DES_IDEA] offered Remediation : Refer to testssl documentation for cipherlist_3DES_IDEA Timestamp : 2026-03-23T15:19:46Z [051] [LOW ] [SSL] testssl: [cipherlist_OBSOLETED] offered Remediation : Refer to testssl documentation for cipherlist_OBSOLETED Timestamp : 2026-03-23T15:19:46Z [052] [LOW ] [SSL] testssl: [cipher-tls1_xc013] TLSv1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_xc013 Timestamp : 2026-03-23T15:19:46Z [053] [LOW ] [SSL] testssl: [cipher-tls1_x2f] TLSv1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_x2f Timestamp : 2026-03-23T15:19:46Z [054] [LOW ] [SSL] testssl: [cipher-tls1_xc014] TLSv1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_xc014 Timestamp : 2026-03-23T15:19:46Z [055] [LOW ] [SSL] testssl: [cipher-tls1_x35] TLSv1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_x35 Timestamp : 2026-03-23T15:19:46Z [056] [MEDIUM ] [SSL] testssl: [cipher-tls1_x0a] TLSv1 x0a DES-CBC3-SHA RSA 3DES 168 TLS_RSA_WITH_3DES_EDE_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_x0a Timestamp : 2026-03-23T15:19:46Z [057] [LOW ] [SSL] testssl: [cipher-tls1_1_xc013] TLSv1.1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_1_xc013 Timestamp : 2026-03-23T15:19:47Z [058] [LOW ] [SSL] testssl: [cipher-tls1_1_x2f] TLSv1.1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_1_x2f Timestamp : 2026-03-23T15:19:47Z [059] [LOW ] [SSL] testssl: [cipher-tls1_1_xc014] TLSv1.1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_1_xc014 Timestamp : 2026-03-23T15:19:47Z [060] [LOW ] [SSL] testssl: [cipher-tls1_1_x35] TLSv1.1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_1_x35 Timestamp : 2026-03-23T15:19:47Z [061] [LOW ] [SSL] testssl: [cipher-tls1_2_xc009] TLSv1.2 xc009 ECDHE-ECDSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_xc009 Timestamp : 2026-03-23T15:19:47Z [062] [LOW ] [SSL] testssl: [cipher-tls1_2_xc00a] TLSv1.2 xc00a ECDHE-ECDSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_xc00a Timestamp : 2026-03-23T15:19:47Z [063] [LOW ] [SSL] testssl: [cipher-tls1_2_xc023] TLSv1.2 xc023 ECDHE-ECDSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_xc023 Timestamp : 2026-03-23T15:19:47Z [064] [LOW ] [SSL] testssl: [cipher-tls1_2_xc024] TLSv1.2 xc024 ECDHE-ECDSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_xc024 Timestamp : 2026-03-23T15:19:47Z [065] [LOW ] [SSL] testssl: [cipher-tls1_2_xc013] TLSv1.2 xc013 ECDHE-RSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_xc013 Timestamp : 2026-03-23T15:19:47Z [066] [LOW ] [SSL] testssl: [cipher-tls1_2_x2f] TLSv1.2 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_x2f Timestamp : 2026-03-23T15:19:47Z [067] [LOW ] [SSL] testssl: [cipher-tls1_2_xc014] TLSv1.2 xc014 ECDHE-RSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_xc014 Timestamp : 2026-03-23T15:19:47Z [068] [LOW ] [SSL] testssl: [cipher-tls1_2_x35] TLSv1.2 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA Remediation : Refer to testssl documentation for cipher-tls1_2_x35 Timestamp : 2026-03-23T15:19:47Z [069] [LOW ] [SSL] testssl: [cipher-tls1_2_xc027] TLSv1.2 xc027 ECDHE-RSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA25 Remediation : Refer to testssl documentation for cipher-tls1_2_xc027 Timestamp : 2026-03-23T15:19:47Z [070] [LOW ] [SSL] testssl: [cipher-tls1_2_x3c] TLSv1.2 x3c AES128-SHA256 RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA256 Remediation : Refer to testssl documentation for cipher-tls1_2_x3c Timestamp : 2026-03-23T15:19:47Z [071] [LOW ] [SSL] testssl: [cipher-tls1_2_xc028] TLSv1.2 xc028 ECDHE-RSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA38 Remediation : Refer to testssl documentation for cipher-tls1_2_xc028 Timestamp : 2026-03-23T15:19:47Z [072] [LOW ] [SSL] testssl: [cipher-tls1_2_x3d] TLSv1.2 x3d AES256-SHA256 RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA256 Remediation : Refer to testssl documentation for cipher-tls1_2_x3d Timestamp : 2026-03-23T15:19:47Z [073] [HIGH ] [SSL] testssl: [cert_keyUsage ] Certificate incorrectly used for key encipherment: 'Digital Signature' Remediation : Refer to testssl documentation for cert_keyUsage Timestamp : 2026-03-23T15:19:47Z [074] [CRITICAL] [SSL] testssl: [cert_chain_of_trust ] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple Remediation : Refer to testssl documentation for cert_chain_of_trust Timestamp : 2026-03-23T15:19:47Z [075] [MEDIUM ] [SSL] testssl: [cert_expirationStatus ] expires < 60 days (52) Remediation : Refer to testssl documentation for cert_expirationStatus Timestamp : 2026-03-23T15:19:47Z [076] [MEDIUM ] [SSL] testssl: [cert_notAfter ] 2026-05-14 18:57 Remediation : Refer to testssl documentation for cert_notAfter Timestamp : 2026-03-23T15:19:48Z [077] [LOW ] [SSL] testssl: [DNS_CAArecord ] -- Remediation : Refer to testssl documentation for DNS_CAArecord Timestamp : 2026-03-23T15:19:48Z [078] [CRITICAL] [SSL] testssl: [cert_chain_of_trust ] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple Remediation : Refer to testssl documentation for cert_chain_of_trust Timestamp : 2026-03-23T15:19:48Z [079] [MEDIUM ] [SSL] testssl: [cert_expirationStatus ] expires < 60 days (52) Remediation : Refer to testssl documentation for cert_expirationStatus Timestamp : 2026-03-23T15:19:48Z [080] [MEDIUM ] [SSL] testssl: [cert_notAfter ] 2026-05-14 18:57 Remediation : Refer to testssl documentation for cert_notAfter Timestamp : 2026-03-23T15:19:48Z [081] [LOW ] [SSL] testssl: [DNS_CAArecord ] -- Remediation : Refer to testssl documentation for DNS_CAArecord Timestamp : 2026-03-23T15:19:48Z [082] [LOW ] [SSL] testssl: [HSTS] not offered Remediation : Refer to testssl documentation for HSTS Timestamp : 2026-03-23T15:19:48Z [083] [MEDIUM ] [SSL] testssl: [security_headers] -- Remediation : Refer to testssl documentation for security_headers Timestamp : 2026-03-23T15:19:48Z [084] [MEDIUM ] [SSL] testssl: [BREACH] potentially VULNERABLE, gzip HTTP compression detected - only supplied '/' tested Remediation : Refer to testssl documentation for BREACH Timestamp : 2026-03-23T15:19:48Z [085] [LOW ] [SSL] testssl: [SWEET32] uses 64 bit block ciphers Remediation : Refer to testssl documentation for SWEET32 Timestamp : 2026-03-23T15:19:48Z [086] [MEDIUM ] [SSL] testssl: [BEAST_CBC_TLS1] ECDHE-RSA-AES128-SHA AES128-SHA ECDHE-RSA-AES256-SHA AES256-SHA DES-CBC3-SHA Remediation : Refer to testssl documentation for BEAST_CBC_TLS1 Timestamp : 2026-03-23T15:19:48Z [087] [LOW ] [SSL] testssl: [BEAST] VULNERABLE -- but also supports higher protocols TLSv1.1 TLSv1.2 (likely mitigated) Remediation : Refer to testssl documentation for BEAST Timestamp : 2026-03-23T15:19:48Z [088] [LOW ] [SSL] testssl: [LUCKY13] potentially vulnerable, uses TLS CBC ciphers Remediation : Refer to testssl documentation for LUCKY13 Timestamp : 2026-03-23T15:19:48Z [089] [MEDIUM ] [SSL] testssl: [overall_grade] B Remediation : Refer to testssl documentation for overall_grade Timestamp : 2026-03-23T15:19:48Z [090] [MEDIUM ] [SSL] Certificate expires in 52 days Evidence : May 14 18:57:50 2026 GMT Remediation : Plan certificate renewal. Timestamp : 2026-03-23T15:19:48Z [091] [MEDIUM ] [SSL] HSTS header not configured Description : Strict-Transport-Security is absent — browsers may access the site over HTTP. Remediation : Add: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload Timestamp : 2026-03-23T15:19:49Z [092] [LOW ] [HEADERS] Permissions-Policy missing Description : The response is missing the 'permissions-policy' security header. Remediation : Add: Permissions-Policy: geolocation=(), microphone=(), camera=() Timestamp : 2026-03-23T15:19:49Z [093] [LOW ] [HEADERS] Cross-Origin-Resource-Policy (CORP) missing Description : The response is missing the 'cross-origin-resource-policy' security header. Remediation : Add: Cross-Origin-Resource-Policy: same-origin Timestamp : 2026-03-23T15:19:49Z [094] [LOW ] [HEADERS] Cross-Origin-Opener-Policy (COOP) missing Description : The response is missing the 'cross-origin-opener-policy' security header. Remediation : Add: Cross-Origin-Opener-Policy: same-origin Timestamp : 2026-03-23T15:19:49Z [095] [LOW ] [HEADERS] X-Content-Type-Options missing — MIME sniffing risk Description : The response is missing the 'x-content-type-options' security header. Remediation : Add: X-Content-Type-Options: nosniff Timestamp : 2026-03-23T15:19:49Z [096] [MEDIUM ] [HEADERS] X-Frame-Options missing — clickjacking risk Description : The response is missing the 'x-frame-options' security header. Remediation : Add: X-Frame-Options: SAMEORIGIN Timestamp : 2026-03-23T15:19:49Z [097] [MEDIUM ] [HEADERS] Content-Security-Policy (CSP) missing Description : The response is missing the 'content-security-policy' security header. Remediation : Implement a strict CSP to mitigate XSS and data injection attacks. Timestamp : 2026-03-23T15:19:49Z [098] [LOW ] [HEADERS] Referrer-Policy missing Description : The response is missing the 'referrer-policy' security header. Remediation : Add: Referrer-Policy: strict-origin-when-cross-origin Timestamp : 2026-03-23T15:19:49Z [099] [LOW ] [HEADERS] Informative header exposed: Server Description : Server reveals technology details via 'Server' header. Evidence : server: cloudflare Remediation : Remove or anonymise the 'Server' header in your server configuration. Timestamp : 2026-03-23T15:19:49Z [100] [MEDIUM ] [HEADERS] HTTP does not redirect to HTTPS (HTTP 200) Description : Requests over HTTP are not automatically upgraded to HTTPS. Evidence : http://example.com → 200 Remediation : Configure a permanent 301 redirect from HTTP to HTTPS. Timestamp : 2026-03-23T15:19:49Z [101] [LOW ] [HEADERS] Cache-Control header missing Description : Without Cache-Control, sensitive pages may be cached by intermediaries. Remediation : Add: Cache-Control: no-store, no-cache on authenticated/sensitive pages. Timestamp : 2026-03-23T15:19:49Z [102] [INFO ] [SQLI] No obvious SQLi on primary URL Description : Manual testing with specific parameters recommended. Timestamp : 2026-03-23T15:20:05Z [103] [INFO ] [CMS] CMS detected: unknown Timestamp : 2026-03-23T15:21:12Z [104] [INFO ] [SSRF] No in-band SSRF detected on common parameters Description : Out-of-band (OOB) SSRF may still exist. Use Burp Collaborator or Interactsh for blind testing. Timestamp : 2026-03-23T15:26:05Z ════════════════════════════════════════════════════════════════ FULL AUDIT LOG ════════════════════════════════════════════════════════════════ [16:15:36] [INFO] Starting websec-audit v1.0.1 | PID: 79121 ══════════════════════════════════════════════════════════════ ▸ DEPENDENCY CHECK ══════════════════════════════════════════════════════════════ [16:15:36] [OK] [required] curl [16:15:36] [OK] [required] nmap [16:15:36] [OK] [optional] nikto [16:15:36] [OK] [optional] sqlmap [16:15:36] [OK] [optional] whatweb [16:15:36] [OK] [optional] wafw00f [16:15:36] [OK] [optional] gobuster [16:15:36] [OK] [optional] ffuf [16:15:36] [OK] [optional] dirb [16:15:36] [OK] [optional] wpscan [16:15:36] [WARN] [optional] droopescan — not found (reduced coverage) [16:15:36] [OK] [optional] sslscan [16:15:36] [OK] [optional] testssl.sh [16:15:36] [WARN] [optional] dalfox — not found (reduced coverage) [16:15:36] [OK] [optional] subjack [16:15:36] [OK] [optional] nuclei [16:15:36] [OK] [optional] subfinder [16:15:36] [WARN] [optional] amass — not found (reduced coverage) [16:15:36] [OK] [optional] dnsrecon [16:15:36] [OK] [optional] host [16:15:36] [OK] [optional] whois [16:15:36] [OK] [optional] dig [16:15:36] [OK] [optional] jq [16:15:36] [OK] [optional] python3 ══════════════════════════════════════════════════════════════ ▸ MODULE 00 — TARGET INFORMATION ══════════════════════════════════════════════════════════════ [16:15:36] [INFO] Target URL : https://example.com [16:15:36] [INFO] Target Domain : example.com [16:15:36] [INFO] Resolved IP : 104.18.27.120 [16:15:36] [INFO] Scheme : https [16:15:36] [INFO] Output Dir : /root/websec-audit/results_example_com_20260323_161531 [16:15:36] [INFO] Timestamp : 20260323_161531 [16:15:36] [INFO] Mode : NORMAL [16:15:36] [INFO] [INIT] Audit started against https://example.com ↳ Resolved IP: 104.18.27.120 | Mode: NORMAL ══════════════════════════════════════════════════════════════ ▸ MODULE 01 — RECONNAISSANCE ══════════════════════════════════════════════════════════════ ──────────────────────────────────────── ● WHOIS Lookup ──────────────────────────────────────── [16:15:36] [OK] WHOIS saved → /root/websec-audit/results_example_com_20260323_161531/recon/whois.txt [16:15:36] [INFO] Expiry : 2026-08-13 [16:15:36] [INFO] [RECON] WHOIS data collected for example.com ↳ Registrar: N/A | Expiry: 2026-08-13 ──────────────────────────────────────── ● DNS Record Enumeration ──────────────────────────────────────── [16:15:37] [OK] DNS records saved → /root/websec-audit/results_example_com_20260323_161531/recon/dns_records.txt [16:15:37] [OK] SPF record present: "v=spf1 -all" [16:15:37] [OK] DMARC record present: "v=DMARC1;p=reject;sp=reject;adkim=s;aspf=s" ──────────────────────────────────────── ● DNS Zone Transfer (AXFR) ──────────────────────────────────────── [16:15:37] [OK] AXFR not permitted (correct) ──────────────────────────────────────── ● Subdomain Enumeration ──────────────────────────────────────── [16:15:37] [INFO] Running subfinder... [16:16:21] [INFO] Running dnsrecon... [16:16:22] [OK] Discovered 37616 unique subdomains → /root/websec-audit/results_example_com_20260323_161531/recon/subdomains.txt [16:16:22] [INFO] [RECON] Subdomain enumeration: 37616 hosts discovered ↳ 0000.example.com 001.example.com 01.example.com 02.example.com 03.example.com 03----may----rrdd.example.com 04.example.com 05----apr----rrdd.example.com 05.example.com 06----apr----rrdd.example.com ↳ Evidence: /root/websec-audit/results_example_com_20260323_161531/recon/subdomains.txt ──────────────────────────────────────── ● Google Dork List ──────────────────────────────────────── [16:16:22] [OK] Google Dorks generated → /root/websec-audit/results_example_com_20260323_161531/recon/google_dorks.txt ══════════════════════════════════════════════════════════════ ▸ MODULE 02 — PORT SCANNING ══════════════════════════════════════════════════════════════ [16:16:22] [INFO] Target : 104.18.27.120 [16:16:22] [INFO] Profile: top-1000 [16:16:22] [INFO] Flags : -sV -sC --open -T4 Nmap 7.93 ( https://nmap.org ) Usage: nmap [Scan Type(s)] [Options] {target specification} TARGET SPECIFICATION: Can pass hostnames, IP addresses, networks, etc. Ex: scanme.nmap.org, microsoft.com/24, 192.168.0.1; 10.0.0-255.1-254 -iL : Input from list of hosts/networks -iR : Choose random targets --exclude : Exclude hosts/networks --excludefile : Exclude list from file HOST DISCOVERY: -sL: List Scan - simply list targets to scan -sn: Ping Scan - disable port scan -Pn: Treat all hosts as online -- skip host discovery -PS/PA/PU/PY[portlist]: TCP SYN/ACK, UDP or SCTP discovery to given ports -PE/PP/PM: ICMP echo, timestamp, and netmask request discovery probes -PO[protocol list]: IP Protocol Ping -n/-R: Never do DNS resolution/Always resolve [default: sometimes] --dns-servers : Specify custom DNS servers --system-dns: Use OS's DNS resolver --traceroute: Trace hop path to each host SCAN TECHNIQUES: -sS/sT/sA/sW/sM: TCP SYN/Connect()/ACK/Window/Maimon scans -sU: UDP Scan -sN/sF/sX: TCP Null, FIN, and Xmas scans --scanflags : Customize TCP scan flags -sI : Idle scan -sY/sZ: SCTP INIT/COOKIE-ECHO scans -sO: IP protocol scan -b : FTP bounce scan PORT SPECIFICATION AND SCAN ORDER: -p : Only scan specified ports Ex: -p22; -p1-65535; -p U:53,111,137,T:21-25,80,139,8080,S:9 --exclude-ports : Exclude the specified ports from scanning -F: Fast mode - Scan fewer ports than the default scan -r: Scan ports sequentially - don't randomize --top-ports : Scan most common ports --port-ratio : Scan ports more common than SERVICE/VERSION DETECTION: -sV: Probe open ports to determine service/version info --version-intensity : Set from 0 (light) to 9 (try all probes) --version-light: Limit to most likely probes (intensity 2) --version-all: Try every single probe (intensity 9) --version-trace: Show detailed version scan activity (for debugging) SCRIPT SCAN: -sC: equivalent to --script=default --script=: is a comma separated list of directories, script-files or script-categories --script-args=: provide arguments to scripts --script-args-file=filename: provide NSE script args in a file --script-trace: Show all data sent and received --script-updatedb: Update the script database. --script-help=: Show help about scripts. is a comma-separated list of script-files or script-categories. OS DETECTION: -O: Enable OS detection --osscan-limit: Limit OS detection to promising targets --osscan-guess: Guess OS more aggressively TIMING AND PERFORMANCE: Options which take