Skip to content

securityheaders follows redirect that doesn't exist #94

@weinzierl

Description

@weinzierl

Submitting weinzierlweb.com to securityheaders.com actually scans unstable.weinzierlweb.com

image

If I'm not completely confused there is no such redirect and has not been in the recent past. There is no HTTP redirect, both domains return 200, serve different pages and show different content in the browser. Their DNS records point to different IPs as follows:

Note that the second domain is IPv6 only.

Other tools properly report the correct site:

image

image

These are not cached reports as you can see from the dates. They were made roughly at the same time I did the securityheaders.com report.

This is most probably a strange and minor corner case but I thought I report it.
I'm curious what is going on here. Thanks for making securityheaders.com freely available!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions