+ Server: nginx
+ The anti-clickjacking X-Frame-Options header is not present.
+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
+ Root page / redirects to:
https://www.byggkontroller.com/
+ No CGI Directories found (use '-C all' to force check all possible dirs)
+ OSVDB-3092: /sitemap.xml: This gives a nice listing of the site content.
+ 7889 requests: 0 error(s) and 4 item(s) reported on remote host
+ End Time: 2021-04-14 xx:59:27 (GMT x) (727 seconds)
---------------------------------------------------------------------------
+ 1 host(s) tested
Status : 301 Moved Permanently
Title : <None>
IP : 178.238.47.90
Country : CZECH REPUBLIC, CZ
Summary : nginx, HTTPServer[nginx], RedirectLocation[
https://www.byggkontroller.com/]
Detected Plugins:
[ HTTPServer ]
HTTP server header string. This plugin also attempts to
identify the operating system from the server header.
String : nginx (from server string)
[ RedirectLocation ]
HTTP Server string location. used with http-status 301 and
302
String :
https://www.byggkontroller.com/ (from location)
[ nginx ]
Nginx (Engine-X) is a free, open-source, high-performance
HTTP server and reverse proxy, as well as an IMAP/POP3
proxy server.
Website :
http://nginx.net/
HTTP Headers:
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Wed, 14 Apr 2021 xx:25:52 GMT x
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Location:
https://www.byggkontroller.com/
xxx report for
https://www.byggkontroller.com/
Status : 200 OK
Title : Kontrollansvarig, KA, Kontrollplan, Besiktningsman, Örebro, Karlstad, Västerås. Mälardalen, Byggkontroller.com
IP : 178.238.47.90
Country : CZECH REPUBLIC, CZ
Summary : nginx, Script[application/javascript,text/javascript], X-UA-Compatible[IE=edge], MetaGenerator[Webnode 2], HTML5, HTTPServer[nginx], Google-Analytics[Universal][UA-797705-6], Adobe-Flash, Open-Graph-Protocol[article], X-Frame-Options[DENY], Cookies[PHPSESSID], Email[stefan@byggkontroller.com], HttpOnly[PHPSESSID], PoweredBy[Webnode]
Detected Plugins:
[ Adobe-Flash ]
This plugin identifies instances of embedded adobe flash
files.
Google Dorks: (1)
Website : https://get.adobe.com/flashplayer/
[ Cookies ]
Display the names of cookies in the HTTP headers. The
values are not returned to save on space.
String : PHPSESSID
[ Email ]
Extract email addresses. Find valid email address and
syntactically invalid email addresses from mailto: link
tags. We match syntactically invalid links containing
mailto: to catch anti-spam email addresses, eg. bob at
gmail.com. This uses the simplified email regular
expression from
http://www.regular-expressions.info/email.html for valid
email address matching.
String : stefan@byggkontroller.com
[ Google-Analytics ]
This plugin identifies the Google Analytics account.
Version : Universal
Account : UA-797705-6
Website : http://www.google.com/analytics/
[ HTML5 ]
HTML version 5, detected by the doctype declaration
[ HTTPServer ]
HTTP server header string. This plugin also attempts to
identify the operating system from the server header.
String : nginx (from server strin g)
[ HttpOnly ]
If the HttpOnly flag is included in the HTTP set-cookie
response header and the browser supports it then the cookie
cannot be accessed through client side script - More Info:
String : PHPSESSID
[ MetaGenerator ]
This plugin identifies meta generator tags and extracts its
value.
String : Webnode 2
[ Open-Graph-Protocol ]
Version : article
[ PoweredBy ]
This plugin identifies instances of 'Powered by x' text and
attempts to extract the value for x.
String : Webnode
[ Script ]
This plugin detects instances of script HTML elements and
returns the script language/type.
String : application/javascript,text/javascript
[ X-Frame-Options ]
This plugin retrieves the X-Frame-Options value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : DENY
[ X-UA-Compatible ]
This plugin retrieves the X-UA-Compatible value from the
HTTP header and meta http-equiv tag. - More Info:
http://msdn.microsoft.com/en-us/library/cc817574.aspx
String : IE=edge
[ nginx ]
Nginx (Engine-X) is a free, open-source, high-performance
HTTP server and reverse proxy, as well as an IMAP/POP3
proxy server.
Website : http://nginx.net/
HTTP Headers:
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 14 Apr 2021 xx:25:54 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Set-Cookie: PHPSESSID=198a8a84xxxxxxxxxxf0e3df5f476986; path=/; domain=byggkontroller.com; HttpOnly
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
X-FRAME-OPTIONS: DENY
Content-Encoding: gzip
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml">
<url>
<loc>https://www.byggkontroller.com/</loc>
</url>
<url>
<loc>https://www.byggkontroller.com/tjanster/</loc>
</url>
<url>
<loc>https://www.byggkontroller.com/kontakt2/</loc>
</url>
<url>
<loc>https://www.byggkontroller.com/om-oss/</loc>
</url>
<url>
<loc>https://www.byggkontroller.com/kontrollansvar-enligt-pbl-ka/</loc>
</url>
<url>
<loc>https://www.byggkontroller.com/entreprenadbesiktningar/</loc>
</url>
<url>
<loc>https://www.byggkontroller.com/bas-p-och-bas-u/</loc>
</url>
<url>
<loc>https://www.byggkontroller.com/skyddsrumssakkunnig/</loc>
</url>
<url>
<loc>https://www.byggkontroller.com/konsultation/</loc>
</url>
<url>
<loc>https://www.byggkontroller.com/garantier/</loc>
</url>
</urlset>
User-agent: psbot
Disallow: /
User-agent: *
Disallow:
Crawl-delay: 10
Sitemap: https://www.byggkontroller.com/sitemap.xml
BURKLETARE:SE
+ Target IP: 46.30.215.39
+ Target Hostname: burkletare.se
+ Target Port: 443
---------------------------------------------------------------------------
+ SSL Info: Subject: /CN=*.burkletare.se
Ciphers: TLS_AES_256_GCM_SHA384
Issuer: /C=US/O=Let's Encrypt/CN=R3
+ Start Time: 2021-04-14 xx:04:45 (GMT x)
---------------------------------------------------------------------------
+ Server: Apache
+ Retrieved via header: 1.1 varnish (Varnish/6.6)
+ The anti-clickjacking X-Frame-Options header is not present.
+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
+ The site uses SSL and the Strict-Transport-Security HTTP header is not defined.
+ The site uses SSL and Expect-CT header is not present.
+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
+ No CGI Directories found (use '-C all' to force check all possible dirs