Security Report Summary
D
Site: | https://www.qatarairways.com/en/Privilege-Club.html | ||
---|---|---|---|
IP Address: | 23.39.41.58 | ||
Report Time: | 26 Aug 2025 19:43:21 UTC | ||
Headers: |
|
||
Advanced: |
|
Missing Headers
Content-Security-Policy | Content Security Policy is an effective measure to protect your site from XSS attacks. By whitelisting sources of approved content, you can prevent the browser from loading malicious assets. |
---|---|
Referrer-Policy | Referrer Policy is a new header that allows a site to control how much information the browser includes with navigations away from a document and should be set by all sites. |
Permissions-Policy | Permissions Policy is a new header that allows a site to control which features and APIs can be used in the browser. |
Warnings
Strict-Transport-Security | The "max-age" directive is too small. The minimum recommended value is 2592000 (30 days). |
---|
Raw Headers
HTTP/2 | 200 |
---|---|
server | Apache |
x-content-type-options | nosniff |
x-xss-protection | 1 |
accept-ranges | bytes |
vary | Accept-Encoding |
access-control-allow-headers | Accept,traceparent,Request-Id,Content-Type,User-Agent |
content-type | text/html; charset=UTF-8 |
x-akamai-transformed | 9 171857 0 pmb=mTOE,4mRUM,2 |
content-encoding | gzip |
date | Tue, 26 Aug 2025 19:43:21 GMT |
set-cookie | AKA_A2=A; expires=Tue, 26-Aug-2025 20:43:21 GMT; path=/; domain=qatarairways.com; secure; HttpOnly |
server-timing | cdn-cache; desc=HIT |
server-timing | edge; dur=44 |
server-timing | origin; dur=0 |
x-frame-options | SAMEORIGIN |
strict-transport-security | max-age=86400 |
set-cookie | bm_ss=ab8e18ef4e; Secure; SameSite=None; Domain=.qatarairways.com; Path=/; HttpOnly; Max-Age=3600 |
set-cookie | _abck=0543A62C37B3E72FFE71193D6935EEAE~-1~YAAQr5vYF+n9ZLWYAQAA2Qvo5w6Ot/9G3CvsMngIR9906pMpmOoDnYPYARh+Z6qkaIMAv8ushIN39IlXy4qMsIKt44KQavaV2nn3t9z1RDPM75Bh1JP+QjsBqNd76YbP/8MSp2eLMJoB3EAraAiTLli2SZHPLmeddn5zsnfntTVsGRe8gO2xi7x4A1n6q0QuWsOqwqUrirlOBB3+F5JiSHlqpySwto4ee0jmbwlaukwC+Ae6493LXhHZ6nyO51vyKNammX6OEhW1VYF7b335gAymQxLiPcP6x6r99A7HJ7AqVWooKvPwgKgga3PPWqaIQAYbywGiXEsE1hpWJ1wIY1POhXA3C0dXkIpbq2UjznIdCjM5Hr0Oej4h6mcmsulylDs70K4AwWVyMgivoXmSOiLcQ0rd3vcqC0AGcswYgF5i7Mc2vg0h/3C0nd4h2HJYeOPsMwu+Wdn9cL2GQek=~-1~-1~-1~~; Domain=.qatarairways.com; Path=/; Expires=Wed, 26 Aug 2026 19:43:21 GMT; Max-Age=31536000; Secure |
set-cookie | ak_bmsc=5B16AE48FE1A7657C6006B32D76A3AB1~000000000000000000000000000000~YAAQr5vYF+r9ZLWYAQAA2Qvo5xzlwSb1HbLrIT5P1VOpeOu1uShHNRxwd5P0D1L4NBw1VFpy9A+s81m9xPHCQF4684TvSBMvsrZOCgFRH2CeiddyDFJMOw0KnZyhYfTsyeawvz4Vqk/wuTypVqJk7yvPsbnXQRasU7yb6l8kFHyt1AWZuhQiDPUso8jmrooSxE2KNAvmLJpM15GIrmlhFw3YMF8d/Gz4jkojjkAjAAI2qjA2Mta0my386gjHHRh+kt9Nq9/MZy3xWubDmHbhlGXvrREzkWuNtcbuWMSEnqc9wM+MX+/+3boeKl9VtjzKp8jlA2ljvLPGLYOc8Zr1uqLOAMzyJIvok3XkMOCav1V/529FFQ2fHf/NI/PxXINkGbpEFzPnY4HbvdfNomn36sk2cA==; Domain=.qatarairways.com; Path=/; Expires=Tue, 26 Aug 2025 21:43:20 GMT; Max-Age=7199 |
set-cookie | bm_mi=EF6773E4FBD837F06E7C02D76065CA2D~YAAQr5vYF+v9ZLWYAQAA2Qvo5xwlB7BWzwNelZEXeblnCp5VR2fPy4YJUlv+dzifJwySaScyjUS79PNRt1bnC6aVxj5iLWk8ofZPYBb9WZRf4fm7jdLEpniRm//P0mmam3OI5+PBiPI5QWphJUerYFWvRxFmGiyF+p6lzfIuDoLirCMIGDHvlpdBosr1bxGDtqWXd8zdZP8DgoTzKpKBvizBuSxESYvnV/31f5CSsjxWV9fK9ogu3nVFLP60lZxTy43cRaI7qWCCwcBVQtunWFXyAuNU2pIu8edHxWySBai8BrPd6qoRJOaQv3lrBMI5v8P1FMYWuNzyOT64Zign9n9ysdGSUL3izZo=~1; Domain=.qatarairways.com; Path=/; Expires=Tue, 26 Aug 2025 19:43:21 GMT; Max-Age=0; Secure |
set-cookie | bm_s=YAAQr5vYF+z9ZLWYAQAA2Qvo5wOrOWPpjrZvzkDWuQ+V2lFdcNnVbKKXCAHeIbVGt1zhLNtROBxc/6uv5uQEzRGmnDbheQt5QNA64QZt86qhYpgZdhYC++vJorKsuGgbW5kAzcFOFqCL8btvjB/pBWaG+CN5J05lBWjGNddzHO1k3IRWnXtxuc14pURey8aaBQLYIgtmhWUZFs7PtfQ24UuKMcp9DBz7/VZvQMImSTQsB182m2V8eK8BFpkNE21wbcQfxU9NI65pLjq1c2f5iJjq9Cyk1t9LrL+OTSzLCciExba46TrR3Xl0fz3UYQ4SnCQmAXB002NeBxwx9uaGUkEPhzVquYJCK7XWRW2HUNgCbcuqqfC6reK57EsA4YrmcDTNkIsT9klKDiztauCQ59Ov7v4YFQI9zkFxhGYquHKSN1i3lUsvmb3sn68D5PkCS/XQnVN606JnvCCey7z5E3fVgmNG/pHwQpJyhTBDjvQ+lj10CzJUHjXgIwy0J0gWsOavEdjpNkoYwkRmUXsPS0sdsKPttqy1d4OmmZ0SGV/VOY7E0LyFoMGjwwgR; Domain=.qatarairways.com; Path=/; Expires=Fri, 26 Sep 2025 19:43:21 GMT; Max-Age=2678400; Secure; HttpOnly |
set-cookie | bm_so=0778FFA05559E05F5A294916A80E34B209B63DF1C91917521176D304982F9569~YAAQr5vYF+39ZLWYAQAA2Qvo5wROxHlN5+2flpbROadQRDeA76mQztCTUR5kVJ8HbnAh/j1aheDHp32TevQ+dhFH/CizUn64mWdcBOtlM1tksgGFDMD7d4FcngZpCX4uwPkKuMkY/8QpDEtnlLMSX0devNRZbUEgCWq5JcDmTPjxrhk4OBACes/mP/meJe6w0OYxfaOummtiIUc6WSdlv/XScKCvHECb1Ie7BohPyZ5uPU4qn4NS9E0yN61s0K0NvEZIOWh1fVkK7eQa/prmp9pGlFasLGQBMTYrWE50ykUs8oPP5dYpk2oNrV2GzlP79F8OS9HtOH9+v2uiNtiejppMXahZsTNJ95wTKU7ZGOIOfQ8Ud+H9S+x7TwapZdjruIMVvaSQwY3ONw92vC4ZSW+l4UE/lk6E37Vdmbam7Y3HRX/8OrvMQSvx6aHC903sHJ3JmMXEElEjSLRzmF2XZ1KY+A+L; Domain=.qatarairways.com; Path=/; Expires=Wed, 27 Aug 2025 19:43:21 GMT; Max-Age=86400; Secure |
set-cookie | bm_sz=C7B738C7EC4052879C0550A8FAC3BCEC~YAAQr5vYF+79ZLWYAQAA2Qvo5xwnidLsexVMSjRDhpsUMHgx8f84S3D34aToWVq37NRMHkPjYb+lj7pgr9Mzto1er+TAmfiiLJ1DYtBYLsSaxTkPg4uw0S1gNcI6e8Nk/J5FYVLsYajdJ7sFb5neyOIGHikNaWXDLOuQ9Yr3j9vC3ydpIg8lnf6rKCBYwQYNWQMdEjiHFUoXgCA/cyq//mu5ljZz05QTVKCqqHLto/Byvd6C0hCiVBqPPKJZ8T9IR+zHGjdXJVQeD5UIkiPGod+WSWeZPgVVGJjXzEqVMVNgnxnQjgMYTaQqS3nfG3ibDyQpvIlA1Img+WiF/sjOjqdqYke9Ximftv5Ks48SjSpeM5IASBwViySs8o8a3d0eKvrdA+tHR6n3mFV/yZimcC8AYsY=~4536114~4539705; Domain=.qatarairways.com; Path=/; Expires=Tue, 26 Aug 2025 23:43:20 GMT; Max-Age=14399 |
server-timing | ak_p; desc="1756237400949_400071599_2378877296_4392_14996_2_9_15";dur=1 |
Upcoming Headers
Cross-Origin-Embedder-Policy | Cross-Origin Embedder Policy allows a site to prevent assets being loaded that do not grant permission to load them via CORS or CORP. |
---|---|
Cross-Origin-Opener-Policy | Cross-Origin Opener Policy allows a site to opt-in to Cross-Origin Isolation in the browser. |
Cross-Origin-Resource-Policy | Cross-Origin Resource Policy allows a resource owner to specify who can load the resource. |
Additional Information
server | This Server header seems to advertise the software being run on the server but you can remove or change this value. |
---|---|
x-content-type-options | X-Content-Type-Options stops a browser from trying to MIME-sniff the content type and forces it to stick with the declared content-type. The only valid value for this header is "X-Content-Type-Options: nosniff". |
x-xss-protection | X-XSS-Protection sets the configuration for the XSS Auditor built into older browsers. The recommended value was "X-XSS-Protection: 1; mode=block" but you should now look at Content Security Policy instead. |
x-frame-options | X-Frame-Options tells the browser whether you want to allow your site to be framed or not. By preventing a browser from framing your site you can defend against attacks like clickjacking. |
strict-transport-security | HTTP Strict Transport Security is an excellent feature to support on your site and strengthens your implementation of TLS by getting the User Agent to enforce the use of HTTPS. |