Security Report Summary
D
Site: | https://www.qatarairways.com/en/Privilege-Club/login.html | ||
---|---|---|---|
IP Address: | 23.72.34.166 | ||
Report Time: | 26 Aug 2025 19:51:43 UTC | ||
Headers: |
|
||
Advanced: |
|
Missing Headers
Content-Security-Policy | Content Security Policy is an effective measure to protect your site from XSS attacks. By whitelisting sources of approved content, you can prevent the browser from loading malicious assets. |
---|---|
Referrer-Policy | Referrer Policy is a new header that allows a site to control how much information the browser includes with navigations away from a document and should be set by all sites. |
Permissions-Policy | Permissions Policy is a new header that allows a site to control which features and APIs can be used in the browser. |
Warnings
Strict-Transport-Security | The "max-age" directive is too small. The minimum recommended value is 2592000 (30 days). |
---|
Raw Headers
HTTP/2 | 200 |
---|---|
server | Apache |
x-content-type-options | nosniff |
x-xss-protection | 1 |
accept-ranges | bytes |
vary | Accept-Encoding |
access-control-allow-headers | Accept,traceparent,Request-Id,Content-Type,User-Agent |
content-type | text/html; charset=UTF-8 |
x-akamai-transformed | 9 - 0 pmb=mTOE,4mRUM,2 |
content-encoding | gzip |
date | Tue, 26 Aug 2025 19:51:43 GMT |
set-cookie | AKA_A2=A; expires=Tue, 26-Aug-2025 20:51:43 GMT; path=/; domain=qatarairways.com; secure; HttpOnly |
server-timing | cdn-cache; desc=REVALIDATE |
server-timing | edge; dur=607 |
server-timing | origin; dur=423 |
x-frame-options | SAMEORIGIN |
strict-transport-security | max-age=86400 |
set-cookie | bm_ss=ab8e18ef4e; Secure; SameSite=None; Domain=.qatarairways.com; Path=/; HttpOnly; Max-Age=3600 |
set-cookie | _abck=707EF120E4C99922B534AD9797CBB956~-1~YAAQpiVIFyE1Z+OYAQAA1Lfv5w69GSqOTiAg5n4Wbh85rf9Bjk/+cfBjrwiSoF2odyZ6euJrJUMHzVVXWvx26/KDq+zJmqZPoID5tE2jefzMSaWdCVj7NCjulmQObXYXcRklbW6uZ1H4ADp8SMVMpjYATSZe8nxl8fsen/1PaDpsF0xNVsGnCL6h9vJd1RiwtA+Yf++M/Tll/fiRF2+9WktgKk00/f6ooZmcQRnbaiUJz0B0EVzPKln3azs3OVFfYFxgBPltmSnVTvVBuATMlTeZ4Abqvzs1ysH6oF3N+5x/QnEkSg64T7m8+JBnrpTgd0jClI7DEcPl4kBIc7BgOe8kkhLhSNFKlpladk+GoQwog8H0oRxEptiPwVPlPuMJZWBrNQmciKQaqmaghsYMDwN/R/WE0qhVMZY1zIDcn6IeiZBzudOd4Geiu44QYrZoRurYo4VoqqKBQhBscdQ=~-1~-1~-1~~; Domain=.qatarairways.com; Path=/; Expires=Wed, 26 Aug 2026 19:51:43 GMT; Max-Age=31536000; Secure |
set-cookie | ak_bmsc=DF3D03A919A7E8B72AAD1ED9A68C1007~000000000000000000000000000000~YAAQpiVIFyI1Z+OYAQAA1Lfv5xyx0czKZ0/nDyaTWj60s17qRAJDi3q8EChEcVT4Bei7WVlO4MKVA8G9EvmbUKOUZ6gc0rBvwzs5IlxogXmdaYI0HsQpQlBsBN7Rrt9Iht1f7mvQtqtcxLYyEo9Ljj+h651VXi7h6pdWDEvi997CRAqDlWnwZmUvPOqLbBMIElc7EIiroV7FTNyEIo1FEm2Uv6jFxxwEmGbC0URBtWH+blxOieORD1XgUwXCb3qNd7XlHk9LMgsnsTIdRCO7lIOUvMK8Lhos+feBiRe4Jt8tAiBZpdzDhH2TnHYkSJjdRgetfwhTs3Td3CoQH0kDuP3QJwHk6k2DwJnxBNtiAjdTP301fWBT7eyH1eKDEooaeuStO0zKThrd/xTnQpd5Bhqk2w==; Domain=.qatarairways.com; Path=/; Expires=Tue, 26 Aug 2025 21:51:42 GMT; Max-Age=7199 |
set-cookie | bm_mi=414DA856105A7CB0C2174327C4077DE0~YAAQpiVIFyM1Z+OYAQAA1Lfv5xxGruDJRHVmaZBq2OPfd1cbg95JRraq7UBPIm1FuAphl4b7ZuomfCVCAZ88vNEOo57FEcmeNOEPodWtYlSzFnVYcX0tPfDPSZEOFzjFRe8g/7cz5mfHcoIYgdy4EubT5/zMOpn/b47/7qtA5gE0jKl1y20UOtXCGPzALpGDk5o14PXkl+nhabO6mz9f48LlyUTJlydsDAcgG/dZxnr/Q0xSJQQeHJFvwYJK3gttvU+sajrl5YPHm0PafsQUURD5ojUDWN+qutHvdDSgz8TQA6UKezkC7WoBdP8VDMl+fJna1fHbl9sFOGpW/iZFa1B42WIBKJuVDnND3rpZBBM=~1; Domain=.qatarairways.com; Path=/; Expires=Tue, 26 Aug 2025 19:51:43 GMT; Max-Age=0; Secure |
set-cookie | bm_s=YAAQpiVIFyQ1Z+OYAQAA1Lfv5wNsi8plDdhnssd/h3PQUIpnkxoNNRUctm0g5Z7R5iXh+3UBaDIJPOnoHOJvXIg9rMK/ug0mrP1P8poxGf8/wlNtYMXwZxrA9j4zitW93MQ9m1DjMQwfXPAq1nixmlaX8Hk1n7jVkYKL6aBAeCGVsSqbiUzaL4wkgfMWggvvn7yB2YU7MbvYFhhwYkFU5NbeNf7xoDnZh7KTa7tDERZcr5kOOmnhyYXdP9f+2hdqslnFkwjmixL6VPWnjIHXWfIsztD2Jgo5mQ3omAjpcC3MhU2nR0CrBl+lRF9rmwUgDNhYJFv/MsnE50Vcew25SGVKEEu8pAwnXzsJZDEXcAdl3/CY7V3L5MTPqJZ0AaFgeBeGfYeewgcoD0mZuejyKXnko1ppBHzHDNGQ29tmt3ixlXCowctAfYZpiv6A+vKKziahFIyIyzS6LDektlwpCPEjGamKi2rlHNaR/qK8al9oLK+BVPVt/wlmwYOPJSliBINW9aVWT2hq5HTmCZMEpKK6cAiASXDdF60YxQVc7SZmsFmxTRJ5uygSBrYx; Domain=.qatarairways.com; Path=/; Expires=Fri, 26 Sep 2025 19:51:43 GMT; Max-Age=2678400; Secure; HttpOnly |
set-cookie | bm_so=5C34D2365FCC5A8B53FCED01D7D88EDE94F219BB9D39B40212CE12A3EC5C1409~YAAQpiVIFyU1Z+OYAQAA1Lfv5wQusO7Pff9Cm2+qAzK+oL0jlQit4MiE6BjOK5EX+ymQiTMMmlbpHSBlsDiheUHw0qmCe16c+ZDkXj5upNYZJFI0/Ud9rZDIadtoT5j5W0Prn2s4+o02zEwop7DcU8fu7yVHKiaR7Gt5YJfH1+Y2FoWK7q5X4mU7ANlCHhODSoxFwkWlyqDg4B0tWGKyotfc6BqQP7CiNZuOEg9orTJhrYHH7X53mOtT7ZWjb0/mTLCd2/nJnW7twRY1G2nyVjku0QhtOb4YZ4W22362Cpm4SlFi5JyW1MZaaOLyPvbz+/ldov01qeQDOWgoveciXEz1+oex8lXTv3PZzfJXm8awQSMAxv1xPgCR8KSAxY7HDZD4q0VtA/xLxgKPodEpT2GWX/2KfMtvyv1OAkrAz3fifrQcUlN4anveWaE+VVXwoNj4finhqd2RzB3393Nrlgo1S+tl; Domain=.qatarairways.com; Path=/; Expires=Wed, 27 Aug 2025 19:51:43 GMT; Max-Age=86400; Secure |
set-cookie | bm_sz=B96A09A0A667E5DA5128311271973177~YAAQpiVIFyY1Z+OYAQAA1Lfv5xzVz5+ZWDaXCyYmYlzBB7bwgiW5qRvk9dfkBPSaEagQuHLxftLsVBEjdHJ4ZYde6zd63tr6ZdBBwG37rY9kfyxGtTSKCICgjOYYuNhDrBTriLjALQGFaCNTssyRDmURyjKOytpfO3RMOigrrriU24eiMkPdDQnA2xz3fkdZ8xVcHThTs5NOkJleW3ZQnHB2q5r7YR3Km6PNcCcGbM+rJqcxJHyCGsKXjENpIU08aPmUzAjt+sjAzOKfzlfd3Yy8vjUVXBej91+GwWO6docUJyfz2nTPoSnZEOt4+3K2T0z1LNIie1YBCHXi5df9WKq9/qwDqdgu8CwK3aPXGMm1JjlM57qsPs/GLSWdeODhgsY9Hd4r+x45LLsi+MbfRX0fGYI=~4538949~3422018; Domain=.qatarairways.com; Path=/; Expires=Tue, 26 Aug 2025 23:51:42 GMT; Max-Age=14399 |
server-timing | ak_p; desc="1756237902714_390604198_136682123_103015_15070_1_4_15";dur=1 |
Upcoming Headers
Cross-Origin-Embedder-Policy | Cross-Origin Embedder Policy allows a site to prevent assets being loaded that do not grant permission to load them via CORS or CORP. |
---|---|
Cross-Origin-Opener-Policy | Cross-Origin Opener Policy allows a site to opt-in to Cross-Origin Isolation in the browser. |
Cross-Origin-Resource-Policy | Cross-Origin Resource Policy allows a resource owner to specify who can load the resource. |
Additional Information
server | This Server header seems to advertise the software being run on the server but you can remove or change this value. |
---|---|
x-content-type-options | X-Content-Type-Options stops a browser from trying to MIME-sniff the content type and forces it to stick with the declared content-type. The only valid value for this header is "X-Content-Type-Options: nosniff". |
x-xss-protection | X-XSS-Protection sets the configuration for the XSS Auditor built into older browsers. The recommended value was "X-XSS-Protection: 1; mode=block" but you should now look at Content Security Policy instead. |
x-frame-options | X-Frame-Options tells the browser whether you want to allow your site to be framed or not. By preventing a browser from framing your site you can defend against attacks like clickjacking. |
strict-transport-security | HTTP Strict Transport Security is an excellent feature to support on your site and strengthens your implementation of TLS by getting the User Agent to enforce the use of HTTPS. |