Security Report Summary
C
Site: | https://www.etihad.com/en-ie/ | ||
---|---|---|---|
IP Address: | 184.31.19.128 | ||
Report Time: | 21 Jun 2025 15:19:53 UTC | ||
Headers: |
|
||
Advanced: |
|
Missing Headers
Content-Security-Policy | Content Security Policy is an effective measure to protect your site from XSS attacks. By whitelisting sources of approved content, you can prevent the browser from loading malicious assets. |
---|---|
Referrer-Policy | Referrer Policy is a new header that allows a site to control how much information the browser includes with navigations away from a document and should be set by all sites. |
Permissions-Policy | Permissions Policy is a new header that allows a site to control which features and APIs can be used in the browser. |
Raw Headers
HTTP/2 | 200 |
---|---|
accept-ranges | bytes |
content-type | text/html; charset=UTF-8 |
etag | W/"2341a-638164309916c-gzip" |
last-modified | Sat, 21 Jun 2025 15:02:05 GMT |
server | Apache |
vary | Accept-Encoding |
x-content-type-options | nosniff |
x-dispatcher | dispatcher1eucentral1-28678506 |
x-frame-options | SAMEORIGIN |
x-vhost | publish |
x-xss-protection | 1; mode=block |
x-akamai-transformed | 9l - 0 pmb=mTOE,2 |
content-encoding | gzip |
cache-control | max-age=91 |
expires | Sat, 21 Jun 2025 15:21:23 GMT |
date | Sat, 21 Jun 2025 15:19:52 GMT |
content-length | 22299 |
strict-transport-security | max-age=31536000 |
x-ey-er | 2.1 |
set-cookie | _abck=7223B9AD99DAB2FB639549A31B992EC5~-1~YAAQP2JkXzosEmGXAQAAcR0Tkw5ZdsjfpbEh95IhYR8s6YAH2t6y5ee65mYq58ULXaL80jB1uHeZxEHmyf6Sg6h6gKtKLpZNaEEWOHG3h1jZ49ojGsKNypumjNO4dvVnYLy4Mp65Oo0Xx14T89rKOVhxvvGRnX+ycuZC+ltaAF02Rb5izLrKYnXPnvk8ZC2VTjlCAM9VtCui4AgGbvoGI/kVYXijhnlFvBKM4337ejVerdzBqYaIdeVWYOCIa4VrvivL0XLBRrQz/MJBzy8qmRQ6QlhVntU/ifAndcu50ona5jFddyEaGBUVpP7D7+QG+yULBGTxTjQ8dIuXV7VyuCRM/NXg5ovdrRWfDWT39Jss+P8I0mn6PcmKTA3s2V6wiz+3Zhc2X940zYKpBt/yy9S2EpAgPzZERGzMZ8vWsBOBXtGCCt9P4vW5E7nwIcUMIhRA/g==~-1~-1~-1; Domain=.etihad.com; Path=/; Expires=Sun, 21 Jun 2026 15:19:52 GMT; Max-Age=31536000; SameSite=None; Secure |
set-cookie | ak_bmsc=3542ADC44F96DF299C95EE174FEE4834~000000000000000000000000000000~YAAQP2JkXzssEmGXAQAAcR0TkxxeCfh2Sc7wDmrLx7WHgnIpXmABnTER66c+tyDMdJ24DBB7u/NpV5Vi2EbMscVD+sgFbtynBYeytXZOUF7fbNGsLItao3sHVnc7xMYsMSyRP3dTyswefLiE+rF2HW8lt1dgi4/1dqdNc6TKo2+XAY792WPp017Qao0znIpVxzBi7mRdeUbSS3sRq2W3g9iYMm8veKDp1e3jYRGOub0/ZAht6rrUTJb5U8c0CbuinZQyxysf+EZGiLUL2yWrcEV42IWLpQOPOMTiN8Jo9SaPNhe83JyTib3fPWSDH66Df0o/Uy0qVGsOYeucLA2GvNuYYuHaVEgQ79wpzv/tL3Wy3dvCyJYcLwG/hPKkpzR+mCqZBgIyfaJ2wwQ=; Domain=.etihad.com; Path=/; Expires=Sat, 21 Jun 2025 17:19:52 GMT; Max-Age=7200; SameSite=None; Secure |
set-cookie | bm_mi=C0B9EEFDF4408FE73BB800FE4772E10D~YAAQP2JkXzwsEmGXAQAAcR0TkxwkL5hY+QUjlG/rrC86QZxYMayCdhAGz0Vy0djnFSlmw9W+TK95egEjO6HbTz6hhv+HJQpP6tn/h4BSdzxz6MwlJ4XtiGnmeuL4gh2BVLdwSig9lkMh3o/LQi9zy2fvyjcKtg85A+1cVgVcG44CE12wOTeEdGMZJ5L6dIqCabKuZri3AuhZ1GGFRH1xP+gzxq6EO6tS7x61ghASB88Tz0MYO867g55RZiJZbWKXr0FmU+B82Gq3wjedUsFwkLo3J+a86rSTlYnSoKp3svFLGR4uxoyow2eyCqTsVMdPWqBQng==~1; Domain=.etihad.com; Path=/; Expires=Sat, 21 Jun 2025 15:19:52 GMT; Max-Age=0; SameSite=None; Secure |
set-cookie | bm_sz=4F5CB1D1FF3FC9E38F94874917D6CC5B~YAAQP2JkXz0sEmGXAQAAcR0TkxyMivHOjPavp+9F83KwzIUg/1M0iPxgt43n5Z36hcjGcerjimH2ZO0GUDV6YEDE2xxqByQsMAuBXVmykOQoKvWfMHvYCVcimdOruw7v0twEtFiWvEECPXfqlrIypvyKXDzjT9BKzGQ0EYVswRT98kZHqN7URlIsi00eOBTbVu/LrNobGKi0sbSthnfzERqvQUcMVBUk5W7Hsxo+xnqbz9eFFT2Q8IStGZyc2qM1DUpKrh99PztL+PEsgzkdWfoers2R1BzejtCwf4yAFZQNAB1KjWuVZfWI97XQETCgBZX86B6aIWhwVhY8+GB8piqgy9yxCDWgoxwx27MVL1AaUgtPl1oHFnVn5fjCkvokW668h5zed1rsWG5hpcM=~3748152~3224369; Domain=.etihad.com; Path=/; Expires=Sat, 21 Jun 2025 19:19:52 GMT; Max-Age=14400; SameSite=None; Secure |
Upcoming Headers
Cross-Origin-Embedder-Policy | Cross-Origin Embedder Policy allows a site to prevent assets being loaded that do not grant permission to load them via CORS or CORP. |
---|---|
Cross-Origin-Opener-Policy | Cross-Origin Opener Policy allows a site to opt-in to Cross-Origin Isolation in the browser. |
Cross-Origin-Resource-Policy | Cross-Origin Resource Policy allows a resource owner to specify who can load the resource. |
Additional Information
server | This Server header seems to advertise the software being run on the server but you can remove or change this value. |
---|---|
x-content-type-options | X-Content-Type-Options stops a browser from trying to MIME-sniff the content type and forces it to stick with the declared content-type. The only valid value for this header is "X-Content-Type-Options: nosniff". |
x-frame-options | X-Frame-Options tells the browser whether you want to allow your site to be framed or not. By preventing a browser from framing your site you can defend against attacks like clickjacking. |
x-xss-protection | X-XSS-Protection sets the configuration for the XSS Auditor built into older browsers. The recommended value was "X-XSS-Protection: 1; mode=block" but you should now look at Content Security Policy instead. |
strict-transport-security | HTTP Strict Transport Security is an excellent feature to support on your site and strengthens your implementation of TLS by getting the User Agent to enforce the use of HTTPS. |