https://www.brq.com/

Rischi · 0 trovati

Copy link

Pratiche che possono comportare rischi per la sicurezza

  • Nessuna classificazione

Intestazioni di sicurezza · 9 trovate

Copy link

Intestazioni di risposta HTTP che possono rafforzare la sicurezza di un'applicazione Web

Ulteriori informazioni...
NomeValoreSupportoInfo
Strict-Transport-Securitymax-age=63072000; includeSubDomains; preloadBuonoDichiara che un sito Web è accessibile solo tramite una connessione sicura (HTTPS).

Fai clic per saperne di più...
X-Frame-OptionsSAMEORIGINBuonoIndica se a un browser deve essere consentito di eseguire il rendering di una pagina in un <frame>, <iframe>, <embed> o <object>.

Fai clic per saperne di più...
X-Content-Type-OptionsnosniffBuonoIndica che i tipi MIME pubblicizzati nelle intestazioni Content-Type devono essere seguiti e non modificati.

Fai clic per saperne di più...
Content-Security-Policybase-uri 'self'; connect-src 'self' *.visualwebsiteoptimizer.com app.vwo.com https://yoast.com/ https://*.clarity.ms https://c.bing.com *.lottiefiles.com/ https://lottie.host/ https://pagead2.googlesyndication.com/ *.hsforms.com *.hs-scripts.com https://hubspot-forms-static-embed.s3.amazonaws.com/ https://cdn.linkedin.oribi.io/ https://px.ads.linkedin.com/ https://www.google-analytics.com https://analytics.google.com https://stats.g.doubleclick.net *.hubapi.com js.hscta.net *.hubspot.com *.hs-banner.com *.hscollectedforms.net https://*.hotjar.com https://*.hotjar.io https://*.hotjar.com https://cdn.cookielaw.org/ https://geolocation.onetrust.com/; default-src 'self' https://*.brq.com https://www.brq.com https://*.clarity.ms https://c.bing.com; font-src 'self' data: https://fonts.gstatic.com https://*.hotjar.com; frame-src 'self' *.visualwebsiteoptimizer.com app.vwo.com https://td.doubleclick.net/ https://www.facebook.com https://bid.g.doubleclick.net https://*.hubspot.com https://*.hs-sites.com https://*.hubspot.net https://play.hubspotvideo.com https://*.hsforms.com https://optimize.google.com https://www.vimeo.com https://youtube.com https://www.youtube.com/ https://www.youtube-nocookie.com/; frame-ancestors 'self' https://*.brq.com https://www.brq.com https://brq.sharepoint.com/ https://www.youtube-nocookie.com/; img-src 'self' data: https://*.brq.com https://www.brq.com https://www.google.com.br *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io https://*.clarity.ms https://c.bing.com https://px.ads.linkedin.com https://fonts.gstatic.com/ https://stats.g.doubleclick.net https://www.facebook.com https://googleads.g.doubleclick.net https://secure.gravatar.com https://ssl.gstatic.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com www.googletagmanager.com https://optimize.google.com js.hscta.net no-cache.hubspot.com *.hubspot.com *.hubspot.net cdn2.hubspot.net *.hsforms.net *.hsforms.com https://themenectar.com https://*.hotjar.com https://*.w.org/ https://*.linkedin.com https://cdn.cookielaw.org/; manifest-src 'self'; media-src 'self' https://*.imgur.com https://*.brq.com https://brq.com/ https://www.brq.com; object-src 'none'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://*.brq.com https://www.brq.com data: https://*.clarity.ms https://c.bing.com https://ssl.google-analytics.com https://tagmanager.google.com https://www.google-analytics.com https://analytics.google.com https://www.googletagmanager.com/ https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com https://optimize.google.com https://ajax.googleapis.com/ https://connect.facebook.net *.hsadspixel.net *.hs.analytics.net js.hscta.net *.hubspot.com static.hsappstatic.net *.usemessages.com *.hs-banner.com https://js.hs-analytics.net/ *.hubspot.net *.hscollectedforms.net *.hsleadflows.net *.hsforms.net *.hsforms.com *.hubspotfeedback.com feedback.hubapi.com *.hs-scripts.com https://snap.licdn.com https://*.hotjar.com https://www.youtube.com https://www.vimeo.com https://cdn.cookielaw.org/ *.visualwebsiteoptimizer.com app.vwo.com; style-src 'report-sample' 'self' 'unsafe-inline' https://fonts.googleapis.com cdn2.hubspot.net https://www.googletagmanager.com/ https://optimize.google.com https://*.hotjar.com *.visualwebsiteoptimizer.com app.vwo.com; child-src 'self' *.hsforms.com https://*.brq.com https://www.brq.com blob:; BuonoControlla le risorse che l'agente utente può caricare per una determinata pagina.

Fai clic per saperne di più...
Referrer-Policystrict-origin-when-cross-originBuonoControlla la quantità di informazioni sul referrer che devono essere incluse nelle richieste.

Fai clic per saperne di più...
Clear-Site-DataBuonoControlla i dati memorizzati da un browser client per le loro origini.

Fai clic per saperne di più...
X-Permitted-Cross-Domain-PoliciesBuonoControlla se un client Web come Adobe Flash Player o Adobe Acrobat dispone dell'autorizzazione per gestire i dati tra domini.

Fai clic per saperne di più...
Permissions-Policygeolocation=(self)NuovoConsenti e nega l'uso delle funzionalità del browser in un documento o iframe.

Fai clic per saperne di più...
Cross-Origin-Embedder-PolicyNuovoConfigura l'incorporamento di risorse multiorigine nel documento.

Fai clic per saperne di più...
Cross-Origin-Opener-Policycredentialless same-originNuovoAssicurati che un documento di livello superiore non condivida un gruppo di contesti di navigazione con documenti di più origini.

Fai clic per saperne di più...
Cross-Origin-Resource-Policycross-originNuovoRichiedere che il browser blocchi le richieste multiorigine/tra siti no-cor alla risorsa specificata.

Fai clic per saperne di più...
X-XSS-Protection1; mode=block; ObsoletoObsoleto. Impedisce il caricamento delle pagine quando rilevano attacchi XSS (cross-site scripting) riflessi.

Fai clic per saperne di più...
Feature-PolicyObsoletoObsoleto. Sostituito dall'intestazione Permissions-Policy.

Fai clic per saperne di più...
Expect-CTObsoletoObsoleto. Accetta la segnalazione e/o l'applicazione dei requisiti di trasparenza dei certificati.

Fai clic per saperne di più...
Public-Key-PinsObsoletoObsoleto. Consente ai siti Web HTTPS di resistere alla rappresentazione da parte di autori di attacchi che utilizzano certificati emessi erroneamente o altrimenti fraudolenti.

Fai clic per saperne di più...

Violazioni della sicurezza · 8 trovate

Copy link

Richieste o risorse che violano le politiche di sicurezza

ViolazioneTipoInfo
Risorsa
https://www.googletagmanager.com/gtag/js?id=G-CLBW3H9CEV&l=dataLayer&cx=c&gtm=45He51d0v899802097za200
Descrizione
Refused to connect to 'https://region1.analytics.google.com/g/collect?v=2&tid=G-CLBW3H9CEV&gtm=45je51d0v899821399z8899802097za200zb899802097&_p=1737057479080&_gaz=1&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102081485~102123608~102198178~102418426&cid=154539335.1737057480&ecid=381513650&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&ec_mode=a&_s=1&sid=1737057479&sct=1&seg=0&dl=https%3A%2F%2Fwww.brq.com%2F&dt=BRQ%20Digital%20Solutions%20%E2%80%94%20Shape%20The%20Future.%20Now&en=page_view&_fv=1&_nsi=1&_ss=1&tfd=4220' because it violates the following Content Security Policy directive: "connect-src 'self' *.visualwebsiteoptimizer.com app.vwo.com https://yoast.com/ https://*.clarity.ms https://c.bing.com *.lottiefiles.com/ https://lottie.host/ https://pagead2.googlesyndication.com/ *.hsforms.com *.hs-scripts.com https://hubspot-forms-static-embed.s3.amazonaws.com/ https://cdn.linkedin.oribi.io/ https://px.ads.linkedin.com/ https://www.google-analytics.com https://analytics.google.com https://stats.g.doubleclick.net *.hubapi.com js.hscta.net *.hubspot.com *.hs-banner.com *.hscollectedforms.net https://*.hotjar.com https://*.hotjar.io https://*.hotjar.com https://cdn.cookielaw.org/ https://geolocation.onetrust.com/".
Criteri di sicurezza dei contenutiControlla le risorse che l'agente utente può caricare per una determinata pagina.

Fai clic per saperne di più...
Risorsa
https://www.googletagmanager.com/gtag/js?id=G-CLBW3H9CEV&l=dataLayer&cx=c&gtm=45He51d0v899802097za200
Descrizione
Refused to connect to 'https://region1.analytics.google.com/g/collect?v=2&tid=G-CLBW3H9CEV&gtm=45je51d0v899821399z8899802097za200zb899802097&_p=1737057479080&_gaz=1&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102081485~102123608~102198178~102418426&cid=154539335.1737057480&ecid=381513650&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&ec_mode=a&_s=1&sid=1737057479&sct=1&seg=0&dl=https%3A%2F%2Fwww.brq.com%2F&dt=BRQ%20Digital%20Solutions%20%E2%80%94%20Shape%20The%20Future.%20Now&en=page_view&_fv=1&_nsi=1&_ss=1&tfd=4220' because it violates the document's Content Security Policy.
Criteri di sicurezza dei contenutiControlla le risorse che l'agente utente può caricare per una determinata pagina.

Fai clic per saperne di più...
Risorsa
https://www.brq.com/
Descrizione
Refused to load the image 'https://www.google.es/ads/ga-audiences?v=1&t=sr&slf_rd=1&_r=4&tid=G-CLBW3H9CEV&cid=154539335.1737057480&gtm=45je51d0v899821399z8899802097za200zb899802097&aip=1&dma=1&dma_cps=syphamo&gcd=13l3l3l2l1l1&npa=1&frm=0&tag_exp=101925629~102067555~102067808~102081485~102123608~102198178~102418426&tag_exp=101925629~102067555~102067808~102081485~102123608~102198178~102418426&z=600349560' because it violates the following Content Security Policy directive: "img-src 'self' data: https://*.brq.com https://www.brq.com https://www.google.com.br *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io https://*.clarity.ms https://c.bing.com https://px.ads.linkedin.com https://fonts.gstatic.com/ https://stats.g.doubleclick.net https://www.facebook.com https://googleads.g.doubleclick.net https://secure.gravatar.com https://ssl.gstatic.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com www.googletagmanager.com https://optimize.google.com js.hscta.net no-cache.hubspot.com *.hubspot.com *.hubspot.net cdn2.hubspot.net *.hsforms.net *.hsforms.com https://themenectar.com https://*.hotjar.com https://*.w.org/ https://*.linkedin.com https://cdn.cookielaw.org/".
Criteri di sicurezza dei contenutiControlla le risorse che l'agente utente può caricare per una determinata pagina.

Fai clic per saperne di più...
Risorsa
https://www.googletagmanager.com/gtag/js?id=AW-452006008
Descrizione
Refused to connect to 'https://www.google.com/ccm/collect?en=page_view&dl=https%3A%2F%2Fwww.brq.com%2F&scrsrc=www.googletagmanager.com&frm=0&rnd=1666373855.1737057483&dt=BRQ%20Digital%20Solutions%20%E2%80%94%20Shape%20The%20Future.%20Now&auid=231864838.1737057483&navt=n&npa=1&did=dZTQ1Zm&gdid=dZTQ1Zm&gtm=45be51d0v9115194007za200zb899802097&gcd=13l3l3l2l1l1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102081485~102123608~102198178&tft=1737057483302&tfd=7621&apve=1' because it violates the following Content Security Policy directive: "connect-src 'self' *.visualwebsiteoptimizer.com app.vwo.com https://yoast.com/ https://*.clarity.ms https://c.bing.com *.lottiefiles.com/ https://lottie.host/ https://pagead2.googlesyndication.com/ *.hsforms.com *.hs-scripts.com https://hubspot-forms-static-embed.s3.amazonaws.com/ https://cdn.linkedin.oribi.io/ https://px.ads.linkedin.com/ https://www.google-analytics.com https://analytics.google.com https://stats.g.doubleclick.net *.hubapi.com js.hscta.net *.hubspot.com *.hs-banner.com *.hscollectedforms.net https://*.hotjar.com https://*.hotjar.io https://*.hotjar.com https://cdn.cookielaw.org/ https://geolocation.onetrust.com/".
Criteri di sicurezza dei contenutiControlla le risorse che l'agente utente può caricare per una determinata pagina.

Fai clic per saperne di più...
Risorsa
https://www.googletagmanager.com/gtag/js?id=AW-452006008
Descrizione
Refused to connect to 'https://region1.analytics.google.com/g/collect?v=2&tid=G-0BKZKD0V2C&gtm=45be51d0v9115194007za200zb899802097&_p=1737057479080&_gaz=1&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102081485~102123608~102198178&gdid=dZTQ1Zm&cid=154539335.1737057480&ecid=1925900934&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&ec_mode=a&_s=1&sid=1737057483&sct=1&seg=0&dl=https%3A%2F%2Fwww.brq.com%2F&dt=BRQ%20Digital%20Solutions%20%E2%80%94%20Shape%20The%20Future.%20Now&en=page_view&_fv=1&_ss=1&_ee=1&tfd=7671' because it violates the following Content Security Policy directive: "connect-src 'self' *.visualwebsiteoptimizer.com app.vwo.com https://yoast.com/ https://*.clarity.ms https://c.bing.com *.lottiefiles.com/ https://lottie.host/ https://pagead2.googlesyndication.com/ *.hsforms.com *.hs-scripts.com https://hubspot-forms-static-embed.s3.amazonaws.com/ https://cdn.linkedin.oribi.io/ https://px.ads.linkedin.com/ https://www.google-analytics.com https://analytics.google.com https://stats.g.doubleclick.net *.hubapi.com js.hscta.net *.hubspot.com *.hs-banner.com *.hscollectedforms.net https://*.hotjar.com https://*.hotjar.io https://*.hotjar.com https://cdn.cookielaw.org/ https://geolocation.onetrust.com/".
Criteri di sicurezza dei contenutiControlla le risorse che l'agente utente può caricare per una determinata pagina.

Fai clic per saperne di più...
Risorsa
https://www.googletagmanager.com/gtag/js?id=AW-452006008
Descrizione
Refused to connect to 'https://region1.analytics.google.com/g/collect?v=2&tid=G-0BKZKD0V2C&gtm=45be51d0v9115194007za200zb899802097&_p=1737057479080&_gaz=1&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102081485~102123608~102198178&gdid=dZTQ1Zm&cid=154539335.1737057480&ecid=1925900934&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&ec_mode=a&_s=1&sid=1737057483&sct=1&seg=0&dl=https%3A%2F%2Fwww.brq.com%2F&dt=BRQ%20Digital%20Solutions%20%E2%80%94%20Shape%20The%20Future.%20Now&en=page_view&_fv=1&_ss=1&_ee=1&tfd=7671' because it violates the document's Content Security Policy.
Criteri di sicurezza dei contenutiControlla le risorse che l'agente utente può caricare per una determinata pagina.

Fai clic per saperne di più...
Risorsa
https://www.brq.com/
Descrizione
Refused to load the image 'https://www.google.es/ads/ga-audiences?v=1&t=sr&slf_rd=1&_r=4&tid=G-0BKZKD0V2C&cid=154539335.1737057480&gtm=45be51d0v9115194007za200zb899802097&aip=1&dma=1&dma_cps=syphamo&gcd=13l3l3l2l1l1&npa=1&frm=0&tag_exp=101925629~102067555~102067808~102081485~102123608~102198178&tag_exp=101925629~102067555~102067808~102081485~102123608~102198178&z=2020910701' because it violates the following Content Security Policy directive: "img-src 'self' data: https://*.brq.com https://www.brq.com https://www.google.com.br *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io https://*.clarity.ms https://c.bing.com https://px.ads.linkedin.com https://fonts.gstatic.com/ https://stats.g.doubleclick.net https://www.facebook.com https://googleads.g.doubleclick.net https://secure.gravatar.com https://ssl.gstatic.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com www.googletagmanager.com https://optimize.google.com js.hscta.net no-cache.hubspot.com *.hubspot.com *.hubspot.net cdn2.hubspot.net *.hsforms.net *.hsforms.com https://themenectar.com https://*.hotjar.com https://*.w.org/ https://*.linkedin.com https://cdn.cookielaw.org/".
Criteri di sicurezza dei contenutiControlla le risorse che l'agente utente può caricare per una determinata pagina.

Fai clic per saperne di più...
Risorsa
https://www.googletagmanager.com/
Descrizione
Refused to frame 'https://www.googletagmanager.com/' because it violates the following Content Security Policy directive: "frame-src 'self' *.visualwebsiteoptimizer.com app.vwo.com https://td.doubleclick.net/ https://www.facebook.com https://bid.g.doubleclick.net https://*.hubspot.com https://*.hs-sites.com https://*.hubspot.net https://play.hubspotvideo.com https://*.hsforms.com https://optimize.google.com https://www.vimeo.com https://youtube.com https://www.youtube.com/ https://www.youtube-nocookie.com/".
Criteri di sicurezza dei contenutiControlla le risorse che l'agente utente può caricare per una determinata pagina.

Fai clic per saperne di più...

Certificati · 20 trovati

Copy link

I certificati SSL/TLS consentono ai siti Web di crittografare le transazioni tra il client e il server e fornire la verifica dell'identità del server

OggettoData di emissioneData di scadenza
*.brq.com12 ago 2024, 00:00:0012 set 2025, 23:59:59
upload.video.google.com9 dic 2024, 08:37:203 mar 2025, 08:37:19
hs-scripts.com24 nov 2024, 01:27:5422 feb 2025, 01:27:53
*.google-analytics.com9 dic 2024, 08:36:183 mar 2025, 08:36:17
*.gstatic.com9 dic 2024, 08:37:203 mar 2025, 08:37:19
*.hotjar.com22 mag 2024, 00:00:0020 giu 2025, 23:59:59
hsadspixel.net8 dic 2024, 05:21:308 mar 2025, 05:21:29
hs-analytics.net5 dic 2024, 00:50:145 mar 2025, 00:50:13
hs-banner.com22 nov 2024, 22:12:5720 feb 2025, 22:12:56
hubspot.com1 dic 2024, 19:14:291 mar 2025, 20:14:28