2018-02-20 website test - hosting provider cookie security

From annawiki
The printable version is no longer supported and may have rendering errors. Please update your browser bookmarks and please use the default browser print function instead.
Mozilla Observatory
Link Score Grade Cookies
https://observatory.mozilla.org/analyze/strato.de 5/100 F No cookies detected
https://observatory.mozilla.org/analyze/ovh.de 0/100 F -20 Cookies set without using the Secure flag or set over http
https://observatory.mozilla.org/analyze/1und1.de 0/100 F -20 Cookies set without using the Secure flag or set over http
https://observatory.mozilla.org/analyze/inwx.de 5/100 F -30 Session cookie set without using the HttpOnly flag
https://observatory.mozilla.org/analyze/do.de 25/100 D- -30 Session cookie set without using the HttpOnly flag
https://observatory.mozilla.org/analyze/all-inkl.com 0/100 F -40 Session cookie set without using the Secure flag or set over http
  • 2018-02-20 an email has been sent to OVH, 1und1, INWX, DO, ALL-inkl to inform them about the issue
    • 2018-02-21 OVH: "Ich werde Ihr Feedback weiterleiten."
    • 2018-02-21 DO: "Ich habe dies an unsere Technik weitergegeben. Diese wird das Überprüfen."

2018-07-07

2018-09-20

  • netcup.de : F, 15/100, 5/11. HTTP Strict Transport Security (HSTS) header not implemented

2018-10-05

  • a1.net : F, 0/100, 6/11. Session cookie set without using the Secure flag or set over HTTP