diff --git a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/budget_page.json b/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/budget_page.json deleted file mode 100644 index d49f91e64d7..00000000000 --- a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/budget_page.json +++ /dev/null @@ -1 +0,0 @@ -{"grade":"F","url":"null","uri":""} \ No newline at end of file diff --git a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/declaration-a11y.json b/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/declaration-a11y.json deleted file mode 100644 index 8044f28e135..00000000000 --- a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/declaration-a11y.json +++ /dev/null @@ -1 +0,0 @@ -{"mention":null} diff --git a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/declaration-rgpd.json b/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/declaration-rgpd.json deleted file mode 100644 index aff77904b3b..00000000000 --- a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/declaration-rgpd.json +++ /dev/null @@ -1 +0,0 @@ -[{"slug":"ml","mention":null,"maxScore":0,"score":0,"missingWords":[],"missingTrackers":[]},{"slug":"pc","mention":null,"maxScore":0,"score":0,"missingWords":[],"missingTrackers":[]}] diff --git a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/dsfr.json b/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/dsfr.json deleted file mode 100644 index fdfe2f294ce..00000000000 --- a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/dsfr.json +++ /dev/null @@ -1 +0,0 @@ -{"detected": false} diff --git a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/http.json b/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/http.json index 846c6ffa27c..60202b006e9 100644 --- a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/http.json +++ b/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/http.json @@ -1 +1 @@ -{"url":"https://api-datasubvention-preprod.osc-secnum-fr1.scalingo.io","algorithm_version":2,"end_time":"Sun, 21 Jan 2024 20:51:20 GMT","grade":"B+","hidden":false,"likelihood_indicator":"MEDIUM","response_headers":{"Access-Control-Allow-Headers":"sentry-trace, baggage","Access-Control-Allow-Origin":"*","Cache-Control":"max-age 1800","Connection":"keep-alive","Content-Length":"174","Content-Security-Policy":"default-src 'none'","Content-Type":"application/json; charset=utf-8","Date":"Sun, 21 Jan 2024 20:51:19 GMT","ETag":"W/\"ae-aaepo/6j8eK5LAryuhO1tqx1gP0\"","Strict-Transport-Security":"max-age=63072000; includeSubDomains; preload","X-Content-Type-Options":"nosniff","X-Frame-Options":"DENY","X-Powered-By":"Express","X-Request-ID":"ef7c3e8f-d1cd-4c01-a28b-324551e106f6"},"scan_id":46827056,"score":80,"start_time":"Sun, 21 Jan 2024 20:51:17 GMT","state":"FINISHED","status_code":200,"tests_failed":1,"tests_passed":11,"tests_quantity":12,"details":{"content-security-policy":{"expectation":"csp-implemented-with-no-unsafe","name":"content-security-policy","output":{"data":{"default-src":["'none'"]},"http":true,"meta":false,"numPolicies":1,"policy":{"antiClickjacking":false,"defaultNone":true,"insecureBaseUri":true,"insecureFormAction":true,"insecureSchemeActive":false,"insecureSchemePassive":false,"strictDynamic":false,"unsafeEval":false,"unsafeInline":false,"unsafeInlineStyle":false,"unsafeObjects":false}},"pass":true,"result":"csp-implemented-with-no-unsafe-default-src-none","score_description":"Content Security Policy (CSP) implemented with default-src 'none' and no 'unsafe'","score_modifier":10},"contribute":{"expectation":"contribute-json-only-required-on-mozilla-properties","name":"contribute","output":{"data":null},"pass":true,"result":"contribute-json-only-required-on-mozilla-properties","score_description":"Contribute.json isn't required on websites that don't belong to Mozilla","score_modifier":0},"cookies":{"expectation":"cookies-secure-with-httponly-sessions","name":"cookies","output":{"data":null,"sameSite":null},"pass":true,"result":"cookies-not-found","score_description":"No cookies detected","score_modifier":0},"cross-origin-resource-sharing":{"expectation":"cross-origin-resource-sharing-not-implemented","name":"cross-origin-resource-sharing","output":{"data":{"acao":"*","clientaccesspolicy":null,"crossdomain":null}},"pass":true,"result":"cross-origin-resource-sharing-implemented-with-public-access","score_description":"Public content is visible via cross-origin resource sharing (CORS) Access-Control-Allow-Origin header","score_modifier":0},"public-key-pinning":{"expectation":"hpkp-not-implemented","name":"public-key-pinning","output":{"data":null,"includeSubDomains":false,"max-age":null,"numPins":null,"preloaded":false},"pass":true,"result":"hpkp-not-implemented","score_description":"HTTP Public Key Pinning (HPKP) header not implemented","score_modifier":0},"redirection":{"expectation":"redirection-to-https","name":"redirection","output":{"destination":"http://api-datasubvention-preprod.osc-secnum-fr1.scalingo.io/","redirects":false,"route":["http://api-datasubvention-preprod.osc-secnum-fr1.scalingo.io/"],"status_code":200},"pass":false,"result":"redirection-missing","score_description":"Does not redirect to an HTTPS site","score_modifier":-20},"referrer-policy":{"expectation":"referrer-policy-private","name":"referrer-policy","output":{"data":null,"http":false,"meta":false},"pass":true,"result":"referrer-policy-not-implemented","score_description":"Referrer-Policy header not implemented","score_modifier":0},"strict-transport-security":{"expectation":"hsts-implemented-max-age-at-least-six-months","name":"strict-transport-security","output":{"data":"max-age=63072000; includeSubDomains; preload","includeSubDomains":true,"max-age":63072000,"preload":true,"preloaded":false},"pass":true,"result":"hsts-implemented-max-age-at-least-six-months","score_description":"HTTP Strict Transport Security (HSTS) header set to a minimum of six months (15768000)","score_modifier":0},"subresource-integrity":{"expectation":"sri-implemented-and-external-scripts-loaded-securely","name":"subresource-integrity","output":{"data":{}},"pass":true,"result":"sri-not-implemented-response-not-html","score_description":"Subresource Integrity (SRI) is only needed for html resources","score_modifier":0},"x-content-type-options":{"expectation":"x-content-type-options-nosniff","name":"x-content-type-options","output":{"data":"nosniff"},"pass":true,"result":"x-content-type-options-nosniff","score_description":"X-Content-Type-Options header set to \"nosniff\"","score_modifier":0},"x-frame-options":{"expectation":"x-frame-options-sameorigin-or-deny","name":"x-frame-options","output":{"data":"DENY"},"pass":true,"result":"x-frame-options-sameorigin-or-deny","score_description":"X-Frame-Options (XFO) header set to SAMEORIGIN or DENY","score_modifier":0},"x-xss-protection":{"expectation":"x-xss-protection-1-mode-block","name":"x-xss-protection","output":{"data":null},"pass":true,"result":"x-xss-protection-not-needed-due-to-csp","score_description":"X-XSS-Protection header not needed due to strong Content Security Policy (CSP) header","score_modifier":0}}} \ No newline at end of file +{"url":"https://api-datasubvention-preprod.osc-secnum-fr1.scalingo.io","algorithm_version":3,"end_time":"Wed, 31 Jan 2024 15:28:31 GMT","grade":"D","hidden":false,"likelihood_indicator":"MEDIUM","response_headers":{"Access-Control-Allow-Credentials":"true","Access-Control-Allow-Headers":"sentry-trace, baggage","Cache-Control":"max-age 1800","Connection":"keep-alive","Content-Length":"174","Content-Security-Policy":"default-src 'none'","Content-Type":"application/json; charset=utf-8","Date":"Wed, 31 Jan 2024 15:28:30 GMT","ETag":"W/\"ae-aaepo/6j8eK5LAryuhO1tqx1gP0\"","Strict-Transport-Security":"max-age=63072000; includeSubDomains; preload","Vary":"Origin","X-Content-Type-Options":"nosniff","X-Frame-Options":"DENY","X-Powered-By":"Express","X-Request-ID":"a28db05a-d1ad-4fc9-8205-8dce888e73a7"},"scan_id":47046645,"score":30,"start_time":"Wed, 31 Jan 2024 15:28:29 GMT","state":"FINISHED","status_code":200,"tests_failed":2,"tests_passed":9,"tests_quantity":11,"details":{"content-security-policy":{"expectation":"csp-implemented-with-no-unsafe","name":"content-security-policy","output":{"data":{"default-src":["'none'"]},"http":true,"meta":false,"numPolicies":1,"policy":{"antiClickjacking":false,"defaultNone":true,"insecureBaseUri":true,"insecureFormAction":true,"insecureSchemeActive":false,"insecureSchemePassive":false,"strictDynamic":false,"unsafeEval":false,"unsafeInline":false,"unsafeInlineStyle":false,"unsafeObjects":false}},"pass":true,"result":"csp-implemented-with-no-unsafe-default-src-none","score_description":"Content Security Policy (CSP) implemented with default-src 'none' and no 'unsafe'","score_modifier":10},"contribute":{"expectation":"contribute-json-only-required-on-mozilla-properties","name":"contribute","output":{"data":null},"pass":true,"result":"contribute-json-only-required-on-mozilla-properties","score_description":"Contribute.json isn't required on websites that don't belong to Mozilla","score_modifier":0},"cookies":{"expectation":"cookies-secure-with-httponly-sessions","name":"cookies","output":{"data":null,"sameSite":null},"pass":true,"result":"cookies-not-found","score_description":"No cookies detected","score_modifier":0},"cross-origin-resource-sharing":{"expectation":"cross-origin-resource-sharing-not-implemented","name":"cross-origin-resource-sharing","output":{"data":{"acao":"https://http-observatory.security.mozilla.org","clientaccesspolicy":null,"crossdomain":null}},"pass":false,"result":"cross-origin-resource-sharing-implemented-with-universal-access","score_description":"Content is visible via cross-origin resource sharing (CORS) file or headers","score_modifier":-50},"redirection":{"expectation":"redirection-to-https","name":"redirection","output":{"destination":"http://api-datasubvention-preprod.osc-secnum-fr1.scalingo.io/","redirects":false,"route":["http://api-datasubvention-preprod.osc-secnum-fr1.scalingo.io/"],"status_code":200},"pass":false,"result":"redirection-missing","score_description":"Does not redirect to an HTTPS site","score_modifier":-20},"referrer-policy":{"expectation":"referrer-policy-private","name":"referrer-policy","output":{"data":null,"http":false,"meta":false},"pass":true,"result":"referrer-policy-not-implemented","score_description":"Referrer-Policy header not implemented","score_modifier":0},"strict-transport-security":{"expectation":"hsts-implemented-max-age-at-least-six-months","name":"strict-transport-security","output":{"data":"max-age=63072000; includeSubDomains; preload","includeSubDomains":true,"max-age":63072000,"preload":true,"preloaded":false},"pass":true,"result":"hsts-implemented-max-age-at-least-six-months","score_description":"HTTP Strict Transport Security (HSTS) header set to a minimum of six months (15768000)","score_modifier":0},"subresource-integrity":{"expectation":"sri-implemented-and-external-scripts-loaded-securely","name":"subresource-integrity","output":{"data":{}},"pass":true,"result":"sri-not-implemented-response-not-html","score_description":"Subresource Integrity (SRI) is only needed for html resources","score_modifier":0},"x-content-type-options":{"expectation":"x-content-type-options-nosniff","name":"x-content-type-options","output":{"data":"nosniff"},"pass":true,"result":"x-content-type-options-nosniff","score_description":"X-Content-Type-Options header set to \"nosniff\"","score_modifier":0},"x-frame-options":{"expectation":"x-frame-options-sameorigin-or-deny","name":"x-frame-options","output":{"data":"DENY"},"pass":true,"result":"x-frame-options-sameorigin-or-deny","score_description":"X-Frame-Options (XFO) header set to SAMEORIGIN or DENY","score_modifier":0},"x-xss-protection":{"expectation":"x-xss-protection-disabled","name":"x-xss-protection","output":{"data":null},"pass":true,"result":"x-xss-protection-not-implemented","score_description":"Deprecated X-XSS-Protection header not implemented","score_modifier":0}}} \ No newline at end of file diff --git a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/nmapvuln.gnmap b/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/nmapvuln.gnmap index 0d9ded254c7..a90f5513aa6 100644 --- a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/nmapvuln.gnmap +++ b/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/nmapvuln.gnmap @@ -1,4 +1,4 @@ -# Nmap 7.92 scan initiated Sun Jan 21 20:58:08 2024 as: nmap -sV --script vulners --script-args mincvss=5.0 -oA /data/nmapvuln api-datasubvention-preprod.osc-secnum-fr1.scalingo.io -Host: 148.253.96.193 (ows-148-253-96-193.cloudgouv-eu-west-1.compute.outscale.com) Status: Up -Host: 148.253.96.193 (ows-148-253-96-193.cloudgouv-eu-west-1.compute.outscale.com) Ports: 80/open/tcp//http///, 443/open/tcp//ssl|https/// Ignored State: filtered (998) -# Nmap done at Sun Jan 21 20:58:56 2024 -- 1 IP address (1 host up) scanned in 48.04 seconds +# Nmap 7.92 scan initiated Wed Jan 31 15:34:59 2024 as: nmap -sV --script vulners --script-args mincvss=5.0 -oA /data/nmapvuln api-datasubvention-preprod.osc-secnum-fr1.scalingo.io +Host: 80.247.12.255 (ows-80-247-12-255.cloudgouv-eu-west-1.compute.outscale.com) Status: Up +Host: 80.247.12.255 (ows-80-247-12-255.cloudgouv-eu-west-1.compute.outscale.com) Ports: 80/open/tcp//http///, 443/open/tcp//ssl|https/// Ignored State: filtered (998) +# Nmap done at Wed Jan 31 15:35:47 2024 -- 1 IP address (1 host up) scanned in 47.98 seconds diff --git a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/nmapvuln.html b/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/nmapvuln.html index a53c2a784c6..c9884d8de25 100644 --- a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/nmapvuln.html +++ b/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/nmapvuln.html @@ -54,7 +54,7 @@
nmap -sV --script vulners --script-args mincvss=5.0 -oA /data/nmapvuln api-datasubvention-preprod.osc-secnum-fr1.scalingo.io-
Sun Jan 21 20:58:08 2024 – Sun Jan 21 20:58:56 2024
1 hosts scanned.
+
Wed Jan 31 15:34:59 2024 – Wed Jan 31 15:35:47 2024
1 hosts scanned.
1 hosts up.
0 hosts down.
148.253.96.193 - api-datasubvention-preprod.osc-secnum-fr1.scalingo.io | +80.247.12.255 - api-datasubvention-preprod.osc-secnum-fr1.scalingo.io | 80 | tcp | http | @@ -188,7 +188,7 @@|
148.253.96.193 - api-datasubvention-preprod.osc-secnum-fr1.scalingo.io | +80.247.12.255 - api-datasubvention-preprod.osc-secnum-fr1.scalingo.io | 443 | tcp | https | diff --git a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/nmapvuln.nmap b/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/nmapvuln.nmap index 00082339eaa..3a4f0d1428f 100644 --- a/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/nmapvuln.nmap +++ b/results/aHR0cHM6Ly9hcGktZGF0YXN1YnZlbnRpb24tcHJlcHJvZC5vc2Mtc2VjbnVtLWZyMS5zY2FsaW5nby5pbw==/nmapvuln.nmap @@ -1,15 +1,15 @@ -# Nmap 7.92 scan initiated Sun Jan 21 20:58:08 2024 as: nmap -sV --script vulners --script-args mincvss=5.0 -oA /data/nmapvuln api-datasubvention-preprod.osc-secnum-fr1.scalingo.io -Nmap scan report for api-datasubvention-preprod.osc-secnum-fr1.scalingo.io (148.253.96.193) +# Nmap 7.92 scan initiated Wed Jan 31 15:34:59 2024 as: nmap -sV --script vulners --script-args mincvss=5.0 -oA /data/nmapvuln api-datasubvention-preprod.osc-secnum-fr1.scalingo.io +Nmap scan report for api-datasubvention-preprod.osc-secnum-fr1.scalingo.io (80.247.12.255) Host is up (0.15s latency). -Other addresses for api-datasubvention-preprod.osc-secnum-fr1.scalingo.io (not scanned): 80.247.12.255 185.21.194.105 80.247.13.145 -rDNS record for 148.253.96.193: ows-148-253-96-193.cloudgouv-eu-west-1.compute.outscale.com +Other addresses for api-datasubvention-preprod.osc-secnum-fr1.scalingo.io (not scanned): 185.21.194.105 80.247.13.145 148.253.96.193 +rDNS record for 80.247.12.255: ows-80-247-12-255.cloudgouv-eu-west-1.compute.outscale.com Not shown: 998 filtered tcp ports (no-response) PORT STATE SERVICE VERSION 80/tcp open http | fingerprint-strings: | GetRequest, HTTPOptions: | HTTP/1.1 404 Not Found -| Date: Sun, 21 Jan 2024 20:58:25 GMT +| Date: Wed, 31 Jan 2024 15:35:17 GMT | Content-Type: text/html | Content-Length: 15436 | Connection: close @@ -19,7 +19,7 @@ PORT STATE SERVICE VERSION | fingerprint-strings: | GetRequest: | HTTP/1.1 404 Not Found -| Date: Sun, 21 Jan 2024 20:58:31 GMT +| Date: Wed, 31 Jan 2024 15:35:23 GMT | Content-Type: text/html | Content-Length: 15436 | Connection: close @@ -27,7 +27,7 @@ PORT STATE SERVICE VERSION |