https://www.dropbox.com/l/AAABve1D7GPhWAZh4XQfLSqf_xHx4yS0WSE

Eingereichte URL:
https://www.dropbox.com/l/AAABve1D7GPhWAZh4XQfLSqf_xHx4yS0WSE
Bericht beendet:

Risiken · 0 gefunden

Praktiken, die ein Sicherheitsrisiko darstellen können

  • Ohne Klassifizierung

Security Header · 7 gefunden

HTTP-Antwortheader, die die Sicherheit einer Web-App erhöhen können

NameWertSupportInfo
Strict-Transport-Securitymax-age=31536000; includeSubDomains max-age=31536000; includeSubDomainsGutartig
X-Frame-OptionsSAMEORIGINGutartig
X-Content-Type-OptionsnosniffGutartig
Content-Security-Policybase-uri 'self'; child-src https://www.dropbox.com/static/serviceworker/ blob:; connect-src https://* ws://127.0.0.1:*/ws blob: wss://dsimports.dropbox.com/; default-src 'none'; font-src https://* data:; form-action 'self' https://www.dropbox.com/ https://dl-web.dropbox.com/ https://photos.dropbox.com/ https://paper.dropbox.com/ https://showcase.dropbox.com/ https://www.hellofax.com/ https://app.hellofax.com/ https://www.hellosign.com/ https://app.hellosign.com/ https://docsend.com/ https://www.docsend.com/ https://help.dropbox.com/ https://navi.dropbox.jp/ https://a.sprig.com/ https://selfguidedlearning.dropboxbusiness.com/ https://instructorledlearning.dropboxbusiness.com/ https://sales.dropboxbusiness.com/ https://accounts.google.com/ https://api.login.yahoo.com/ https://login.yahoo.com/ https://experience.dropbox.com/ https://pal-test.adyen.com https://2e83413d8036243b-Dropbox-pal-live.adyenpayments.com/ https://onedrive.live.com/picker; frame-src https://* carousel: dbapi-6: dbapi-7: dbapi-8: dropbox-client: itms-apps: itms-appss:; img-src https://* data: blob:; media-src https://* blob:; object-src 'self' https://cfl.dropboxstatic.com/static/ https://www.dropboxstatic.com/static/; report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-whitelist; script-src 'unsafe-eval' 'inline-speculation-rules' https://www.dropbox.com/static/api/ https://www.dropbox.com/pithos/* https://www.dropbox.com/page_success/ https://cfl.dropboxstatic.com/static/ https://www.dropboxstatic.com/static/ https://accounts.google.com/gsi/client https://canny.io/sdk.js https://www.paypal.com/sdk/js 'nonce-oWf2ROleM11fJ97LN4i3'; style-src https://* 'unsafe-inline' 'unsafe-eval'; worker-src https://www.dropbox.com/static/serviceworker/ https://www.dropbox.com/encrypted_folder_download/service_worker.js https://www.dropbox.com/service_worker.js blob:; script-src 'unsafe-eval' 'strict-dynamic' 'nonce-oWf2ROleM11fJ97LN4i3' 'nonce-0kiDhCW5XRoyDG8TqKCo'Gutartig
Referrer-Policystrict-origin-when-cross-originGutartig
Clear-Site-DataGutartig
X-Permitted-Cross-Domain-PoliciesnoneGutartig
Permissions-PolicyNeu
Cross-Origin-Embedder-PolicyNeu
Cross-Origin-Opener-PolicyNeu
Cross-Origin-Resource-PolicyNeu
X-XSS-Protection1; mode=blockVeraltet
Feature-PolicyVeraltet
Expect-CTVeraltet
Public-Key-PinsVeraltet

Sicherheitsverstöße · 0 gefunden

Anfragen oder Ressourcen, die gegen Sicherheitsrichtlinien verstoßen

  • Keine gefunden

Zertifikate · 1 gefunden

SSL/TLS-Zertifikate ermöglichen es Websites, Transaktionen zwischen dem Client und dem Server zu verschlüsseln und die Identität des Servers zu überprüfen.

GegenstandAusstellungsdatumAblaufdatum
*.dropbox.com12. Nov. 2024, 00:00:008. Dez. 2025, 23:59:59