已提交的 URL:
https://a856-exams.nyc.gov/OASysWeb/exams
報告完成時間:
公用

風險 · 找到 0 個

複製連結

可能帶來安全風險的做法

  • 無分類

安全違規 · 找到 13 個

複製連結

違反安全性原則的要求或資源

違規類型資訊
資源
https://www.googletagmanager.com/gtm.js?id=GTM-T9JWWJBX
描述
Refused to load the script 'https://connect.facebook.net/en_US/fbevents.js' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' 'unsafe-inline' data: *.gstatic.com:* *.google.com:* *.googleapis.com:* https://a856-exams.nyc.gov:* https://www.googletagmanager.com:* http://www.nyc.gov:* https://www.google-analytics.com:* https://msswva-dcsidvp.csc.nycnet:*". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://a856-exams.nyc.gov/OASysWeb/polyfills.59f6d031a2018c9c9223.js
描述
Refused to connect to 'https://ad.doubleclick.net/activity;src=13992923;type=landi0;cat=retar0;ord=3642808423525;npa=0;auiddc=1930602742.1746470925;uaa=;uab=;uafvl=;uamb=0;uam=;uap=;uapv=;uaw=0;pscdl=noapi;frm=0;_tu=KlA;gtm=45fe5510h1v9188121765z89209763928za200zb9209763928;gcd=13l3l3l3l1l1;dma=0;dc_fmt=3;tag_exp=101509157~102015666~103101747~103101749~103116026~103200004~103233427~103251618~103251620~103252644~103252646;ptag_exp=101509156~103101750~103101752~103116026~103200004~103233424~103251618~103251620~103252644~103252646;epver=2;dc_random=1746470924850;~oref=https%3A%2F%2Fa856-exams.nyc.gov%2FOASysWeb%2Fexams?' because it violates the following Content Security Policy directive: "default-src 'self' 'unsafe-eval' 'unsafe-inline' data: *.gstatic.com:* *.google.com:* *.googleapis.com:* https://a856-exams.nyc.gov:* https://www.googletagmanager.com:* http://www.nyc.gov:* https://www.google-analytics.com:* https://msswva-dcsidvp.csc.nycnet:*". Note that 'connect-src' was not explicitly set, so 'default-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://a856-exams.nyc.gov/OASysWeb/polyfills.59f6d031a2018c9c9223.js
描述
Refused to connect to 'https://ad.doubleclick.net/activity;src=13992923;type=landi0;cat=retar0;ord=3642808423525;npa=0;auiddc=1930602742.1746470925;uaa=;uab=;uafvl=;uamb=0;uam=;uap=;uapv=;uaw=0;pscdl=noapi;frm=0;_tu=KlA;gtm=45fe5510h1v9188121765z89209763928za200zb9209763928;gcd=13l3l3l3l1l1;dma=0;dc_fmt=3;tag_exp=101509157~102015666~103101747~103101749~103116026~103200004~103233427~103251618~103251620~103252644~103252646;ptag_exp=101509156~103101750~103101752~103116026~103200004~103233424~103251618~103251620~103252644~103252646;epver=2;dc_random=1746470924850;~oref=https%3A%2F%2Fa856-exams.nyc.gov%2FOASysWeb%2Fexams?' because it violates the document's Content Security Policy.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://a856-exams.nyc.gov/OASysWeb/exams
描述
Refused to load the image 'https://ad.doubleclick.net/activity;src=13992923;type=landi0;cat=retar0;ord=3642808423525;npa=0;auiddc=1930602742.1746470925;uaa=;uab=;uafvl=;uamb=0;uam=;uap=;uapv=;uaw=0;pscdl=noapi;frm=0;_tu=KlA;gtm=45fe5510h1v9188121765z89209763928za200zb9209763928;gcd=13l3l3l3l1l1;dma=0;dc_fmt=11;tag_exp=101509157~102015666~103101747~103101749~103116026~103200004~103233427~103251618~103251620~103252644~103252646;ptag_exp=101509156~103101750~103101752~103116026~103200004~103233424~103251618~103251620~103252644~103252646;epver=2;dc_random=1746470924850;~oref=https%3A%2F%2Fa856-exams.nyc.gov%2FOASysWeb%2Fexams?' because it violates the following Content Security Policy directive: "default-src 'self' 'unsafe-eval' 'unsafe-inline' data: *.gstatic.com:* *.google.com:* *.googleapis.com:* https://a856-exams.nyc.gov:* https://www.googletagmanager.com:* http://www.nyc.gov:* https://www.google-analytics.com:* https://msswva-dcsidvp.csc.nycnet:*". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtag/js?id=AW-11426691503&l=dataLayer&cx=c&gtm=45He5510h1v9209763928za200&tag_exp=101509156~103101750~103101752~103116026~103200004~103233424~103251618~103251620~103252644~103252646
描述
Refused to load the script 'https://googleads.g.doubleclick.net/pagead/viewthroughconversion/11426691503/?random=1746470924964&cv=11&fst=1746470924964&bg=ffffff&guid=ON&async=1&gtm=45be5510h1z89209763928za200zb9209763928&gcd=13l3l3l3l1l1&dma=0&tag_exp=101509157~103101747~103101749~103116026~103200004~103233427~103251618~103251620~103252644~103252646&ptag_exp=101509156~103101750~103101752~103116026~103200004~103233424~103251618~103251620~103252644~103252646&u_w=1&u_h=1&url=https%3A%2F%2Fa856-exams.nyc.gov%2FOASysWeb%2Fexams&hn=www.googleadservices.com&frm=0&tiba=OAsys%20-%20OAsys&npa=0&pscdl=noapi&auid=1930602742.1746470925&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&fdr=QA&data=event%3Dgtag.config&rfmt=3&fmt=4' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' 'unsafe-inline' data: *.gstatic.com:* *.google.com:* *.googleapis.com:* https://a856-exams.nyc.gov:* https://www.googletagmanager.com:* http://www.nyc.gov:* https://www.google-analytics.com:* https://msswva-dcsidvp.csc.nycnet:*". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtag/js?id=AW-11426691503&l=dataLayer&cx=c&gtm=45He5510h1v9209763928za200&tag_exp=101509156~103101750~103101752~103116026~103200004~103233424~103251618~103251620~103252644~103252646
描述
Refused to load the script 'https://googleads.g.doubleclick.net/pagead/viewthroughconversion/11426691503/?random=1746470925040&cv=11&fst=1746470925040&bg=ffffff&guid=ON&async=1&gtm=45be5510h1z89209763928za200zb9209763928&gcd=13l3l3l3l1l1&dma=0&tag_exp=101509157~103101747~103101749~103116026~103200004~103233427~103251618~103251620~103252644~103252646&ptag_exp=101509156~103101750~103101752~103116026~103200004~103233424~103251618~103251620~103252644~103252646&u_w=1&u_h=1&url=https%3A%2F%2Fa856-exams.nyc.gov%2FOASysWeb%2Fexams&hn=www.googleadservices.com&frm=0&tiba=OAsys%20-%20OAsys&npa=0&pscdl=noapi&auid=1930602742.1746470925&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&fdr=QA&_tu=Cg&rfmt=3&fmt=4' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' 'unsafe-inline' data: *.gstatic.com:* *.google.com:* *.googleapis.com:* https://a856-exams.nyc.gov:* https://www.googletagmanager.com:* http://www.nyc.gov:* https://www.google-analytics.com:* https://msswva-dcsidvp.csc.nycnet:*". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/
描述
Refused to frame 'https://13992923.fls.doubleclick.net/' because it violates the following Content Security Policy directive: "default-src 'self' data: *.gstatic.com:* *.google.com:* *.googleapis.com:* https://a856-exams.nyc.gov:* https://www.googletagmanager.com:* http://www.nyc.gov:* https://www.google-analytics.com:* https://msswva-dcsidvp.csc.nycnet:*". Note that 'frame-src' was not explicitly set, so 'default-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtm.js?id=GTM-T9JWWJBX
描述
Refused to load the script 'https://connect.facebook.net/en_US/fbevents.js' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' 'unsafe-inline' data: *.gstatic.com:* *.google.com:* *.googleapis.com:* https://a856-exams.nyc.gov:* https://www.googletagmanager.com:* http://www.nyc.gov:* https://www.google-analytics.com:* https://msswva-dcsidvp.csc.nycnet:*". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://a856-exams.nyc.gov/OASysWeb/polyfills.59f6d031a2018c9c9223.js
描述
Refused to connect to 'https://ad.doubleclick.net/activity;src=13992923;type=landi0;cat=retar0;ord=2462985981204;npa=0;auiddc=1930602742.1746470925;uaa=;uab=;uafvl=;uamb=0;uam=;uap=;uapv=;uaw=0;pscdl=noapi;frm=0;_tu=KlA;gtm=45fe5510h1v9188121765z89209763928za200zb9209763928;gcd=13l3l3l3l1l1;dma=0;dc_fmt=3;tag_exp=101509157~102015666~103101747~103101749~103116026~103200004~103233427~103251618~103251620~103252644~103252646;ptag_exp=101509156~103101750~103101752~103116026~103200004~103233424~103251618~103251620~103252644~103252646;epver=2;dc_random=1746470925328;~oref=https%3A%2F%2Fa856-exams.nyc.gov%2FOASysWeb%2Fexams?' because it violates the following Content Security Policy directive: "default-src 'self' 'unsafe-eval' 'unsafe-inline' data: *.gstatic.com:* *.google.com:* *.googleapis.com:* https://a856-exams.nyc.gov:* https://www.googletagmanager.com:* http://www.nyc.gov:* https://www.google-analytics.com:* https://msswva-dcsidvp.csc.nycnet:*". Note that 'connect-src' was not explicitly set, so 'default-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://a856-exams.nyc.gov/OASysWeb/polyfills.59f6d031a2018c9c9223.js
描述
Refused to connect to 'https://ad.doubleclick.net/activity;src=13992923;type=landi0;cat=retar0;ord=2462985981204;npa=0;auiddc=1930602742.1746470925;uaa=;uab=;uafvl=;uamb=0;uam=;uap=;uapv=;uaw=0;pscdl=noapi;frm=0;_tu=KlA;gtm=45fe5510h1v9188121765z89209763928za200zb9209763928;gcd=13l3l3l3l1l1;dma=0;dc_fmt=3;tag_exp=101509157~102015666~103101747~103101749~103116026~103200004~103233427~103251618~103251620~103252644~103252646;ptag_exp=101509156~103101750~103101752~103116026~103200004~103233424~103251618~103251620~103252644~103252646;epver=2;dc_random=1746470925328;~oref=https%3A%2F%2Fa856-exams.nyc.gov%2FOASysWeb%2Fexams?' because it violates the document's Content Security Policy.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtag/js?id=AW-11426691503&l=dataLayer&cx=c&gtm=45He5510h1v9209763928za200&tag_exp=101509156~103101750~103101752~103116026~103200004~103233424~103251618~103251620~103252644~103252646
描述
Refused to load the script 'https://googleads.g.doubleclick.net/pagead/viewthroughconversion/11426691503/?random=1746470925349&cv=11&fst=1746470925349&bg=ffffff&guid=ON&async=1&gtm=45be5510h1z89209763928za200zb9209763928&gcd=13l3l3l3l1l1&dma=0&tag_exp=101509157~103101747~103101749~103116026~103200004~103233427~103251618~103251620~103252644~103252646&ptag_exp=101509156~103101750~103101752~103116026~103200004~103233424~103251618~103251620~103252644~103252646&u_w=1&u_h=1&url=https%3A%2F%2Fa856-exams.nyc.gov%2FOASysWeb%2Fexams&hn=www.googleadservices.com&frm=0&tiba=OAsys%20-%20OAsys&npa=0&pscdl=noapi&auid=1930602742.1746470925&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&fdr=QA&_tu=Kg&rfmt=3&fmt=4' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' 'unsafe-inline' data: *.gstatic.com:* *.google.com:* *.googleapis.com:* https://a856-exams.nyc.gov:* https://www.googletagmanager.com:* http://www.nyc.gov:* https://www.google-analytics.com:* https://msswva-dcsidvp.csc.nycnet:*". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://a856-exams.nyc.gov/OASysWeb/exams
描述
Refused to load the image 'https://ad.doubleclick.net/activity;src=13992923;type=landi0;cat=retar0;ord=2462985981204;npa=0;auiddc=1930602742.1746470925;uaa=;uab=;uafvl=;uamb=0;uam=;uap=;uapv=;uaw=0;pscdl=noapi;frm=0;_tu=KlA;gtm=45fe5510h1v9188121765z89209763928za200zb9209763928;gcd=13l3l3l3l1l1;dma=0;dc_fmt=11;tag_exp=101509157~102015666~103101747~103101749~103116026~103200004~103233427~103251618~103251620~103252644~103252646;ptag_exp=101509156~103101750~103101752~103116026~103200004~103233424~103251618~103251620~103252644~103252646;epver=2;dc_random=1746470925328;~oref=https%3A%2F%2Fa856-exams.nyc.gov%2FOASysWeb%2Fexams?' because it violates the following Content Security Policy directive: "default-src 'self' 'unsafe-eval' 'unsafe-inline' data: *.gstatic.com:* *.google.com:* *.googleapis.com:* https://a856-exams.nyc.gov:* https://www.googletagmanager.com:* http://www.nyc.gov:* https://www.google-analytics.com:* https://msswva-dcsidvp.csc.nycnet:*". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/
描述
Refused to frame 'https://13992923.fls.doubleclick.net/' because it violates the following Content Security Policy directive: "default-src 'self' data: *.gstatic.com:* *.google.com:* *.googleapis.com:* https://a856-exams.nyc.gov:* https://www.googletagmanager.com:* http://www.nyc.gov:* https://www.google-analytics.com:* https://msswva-dcsidvp.csc.nycnet:*". Note that 'frame-src' was not explicitly set, so 'default-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...

憑證 · 找到 6 個

複製連結

SSL/TLS 憑證可讓網站加密用戶端與伺服器之間的交易,並提供伺服器身分識別驗證

主旨核發日期到期日
a856-exams.nyc.gov
*.google-analytics.com
*.google.com
www.google.com
upload.video.google.com
*.gstatic.com