No Security Risks Detected
This domain appears to be safe and secure
Disclaimer: This assessment is based on automated analysis of publicly available information. Results are for informational purposes only. For critical applications, consult security professionals.
Scan Information
Refresh page after 10 minutes
for updated results
Page Information
Host Information
Technologies
SSL Certificate
Performance Statistics
HTTP Headers
Technology Stack Analysis
Bootstrap
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
Handlebars
Handlebars is a JavaScript library used to create reusable webpage templates.
jQuery
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
HSTS
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
Cloudflare
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
HTTP/3
HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
External Links 86
https://aws.amazon.com/blogs/security/how-to-get-ready-for-certificate-transparency/
aws.amazon.com
https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/best-practices.html
docs.aws.amazon.com
https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-cloudfront-distribution-customoriginconfig.html
docs.aws.amazon.com
https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-cloudfront-distribution-viewercertificate.html
docs.aws.amazon.com
https://docs.aws.amazon.com/awscloudtrail/latest/userguide/best-practices-security.html
docs.aws.amazon.com
https://docs.aws.amazon.com/awscloudtrail/latest/userguide/encrypting-cloudtrail-log-files-with-aws-kms.html
docs.aws.amazon.com
https://docs.aws.amazon.com/awscloudtrail/latest/userguide/logging-data-events-with-cloudtrail.html
docs.aws.amazon.com
https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-concepts.html#cloudtrail-concepts-global-service-events
docs.aws.amazon.com
https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-log-file-validation-intro.html
docs.aws.amazon.com
https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/AlarmThatSendsEmail.html
docs.aws.amazon.com
https://aws.amazon.com/blogs/mt/aws-config-best-practices/
aws.amazon.com
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html
docs.aws.amazon.com
https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-cis-controls.html#securityhub-cis-controls-4.3
docs.aws.amazon.com
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html
docs.aws.amazon.com
https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html
docs.aws.amazon.com
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-modifying-snapshot-permissions.html
docs.aws.amazon.com
https://aws.amazon.com/security/security-bulletins/reminder-about-safely-sharing-and-using-public-amis/
aws.amazon.com
https://docs.aws.amazon.com/elasticloadbalancing/latest/classic/access-log-collection.html
docs.aws.amazon.com
https://docs.aws.amazon.com/elasticloadbalancing/latest/classic/elb-listener-config.html
docs.aws.amazon.com
https://docs.aws.amazon.com/elasticloadbalancing/latest/classic/elb-security-policy-table.html
docs.aws.amazon.com
https://docs.aws.amazon.com/elasticloadbalancing/latest/APIReference/API_LoadBalancerAttribute.html
docs.aws.amazon.com
https://medium.com/@emilefugulin/http-desync-attacks-with-python-and-aws-1ba07d2c860f
medium.com
https://99designs.com/blog/engineering/request-smuggling/
99designs.com
https://portswigger.net/web-security/request-smuggling
portswigger.net
https://docs.aws.amazon.com/elasticloadbalancing/latest/application/application-load-balancers.html#deletion-protection
docs.aws.amazon.com
https://docs.aws.amazon.com/elasticloadbalancing/latest/application/load-balancer-access-logs.html
docs.aws.amazon.com
https://docs.aws.amazon.com/elasticloadbalancing/latest/network/load-balancer-access-logs.html
docs.aws.amazon.com
https://docs.aws.amazon.com/elasticloadbalancing/latest/classic/elb-https-load-balancers.html
docs.aws.amazon.com
https://docs.aws.amazon.com/elasticloadbalancing/latest/application/create-https-listener.html
docs.aws.amazon.com
https://docs.aws.amazon.com/elasticloadbalancing/latest/network/create-tls-listener.html
docs.aws.amazon.com
https://docs.aws.amazon.com/elasticloadbalancing/latest/application/create-https-listener.html#describe-ssl-policies
docs.aws.amazon.com
https://research.nccgroup.com/2019/12/18/demystifying-aws-assumerole-and-stsexternalid/
research.nccgroup.com
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create_for-user_externalid.html
docs.aws.amazon.com
https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#rotate-credentials
docs.aws.amazon.com
https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_notaction.html
docs.aws.amazon.com
https://aws.amazon.com/blogs/security/back-to-school-understanding-the-iam-policy-grammar/
aws.amazon.com
https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html
docs.aws.amazon.com
https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-cis-controls.html#securityhub-cis-controls-1.9
docs.aws.amazon.com
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_best-practices_mgmt-acct.html#best-practices_mgmt-acct_complex-password
docs.aws.amazon.com
https://docs.aws.amazon.com/organizations/latest/userguide/best-practices_member-acct.html#best-practices_mbr-acct_complex-password
docs.aws.amazon.com
https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-cis-controls.html#securityhub-cis-controls-1.11
docs.aws.amazon.com
https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-cis-controls.html#securityhub-cis-controls-1.10
docs.aws.amazon.com
https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-cis-controls.html#securityhub-cis-controls-1.13
docs.aws.amazon.com
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_best-practices_mgmt-acct.html#best-practices_mgmt-acct_mfa
docs.aws.amazon.com
https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#best-practice-managed-vs-inline
docs.aws.amazon.com
https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_managed-vs-inline.html
docs.aws.amazon.com
https://docs.aws.amazon.com/general/latest/gr/aws-access-keys-best-practices.html
docs.aws.amazon.com
https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#use-groups-for-permissions
docs.aws.amazon.com
https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_managed-vs-inline.html#customer-managed-policies
docs.aws.amazon.com
https://blog.lightspin.io/aws-iam-groups-authorization-bypass
blog.lightspin.io
https://github.com/lightspin-tech/red-shadow
github.com
https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-cis-controls.html#securityhub-standards-cis-controls-1.1
docs.aws.amazon.com
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_best-practices_mgmt-acct.html#best-practices_mgmt-use
docs.aws.amazon.com
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_best-practices_mgmt-acct.html#best-practices_mgmt-acct_review-access
docs.aws.amazon.com
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_best-practices_mgmt-acct.html#best-practices_mgmt-acct_document-processes
docs.aws.amazon.com
https://docs.aws.amazon.com/general/latest/gr/aws_tasks-that-require-root.html
docs.aws.amazon.com
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_best-practices_mgmt-acct.html#best-practices_mgmt-acct_monitor-access
docs.aws.amazon.com
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_passwords_admin-change-user.html
docs.aws.amazon.com
https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#enable-mfa-for-privileged-users
docs.aws.amazon.com
https://docs.aws.amazon.com/organizations/latest/userguide/best-practices_member-acct.html#best-practices_mbr-acct_mfa
docs.aws.amazon.com
https://aws.amazon.com/about-aws/whats-new/2019/11/identify-unused-iam-roles-easily-and-remove-them-confidently-by-using-the-last-used-timestamp/
aws.amazon.com
https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html
docs.aws.amazon.com
https://aws.amazon.com/blogs/database/best-practices-for-upgrading-amazon-rds-to-major-and-minor-versions-of-postgresql/
aws.amazon.com
https://aws.amazon.com/about-aws/whats-new/2018/12/amazon-rds-enhances-auto-minor-version-upgrades/
aws.amazon.com
https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL-certificate-rotation.html
docs.aws.amazon.com
https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_WorkingWithAutomatedBackups.html
docs.aws.amazon.com
https://aws.amazon.com/rds/details/backup/
aws.amazon.com
https://aws.amazon.com/rds/faqs/
aws.amazon.com
https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Overview.Encryption.html
docs.aws.amazon.com
https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_ShareSnapshot.html
docs.aws.amazon.com
https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_VPC.WorkingWithRDSInstanceinaVPC.html#USER_VPC.Hiding
docs.aws.amazon.com
https://aws.amazon.com/rds/features/multi-az/
aws.amazon.com
https://docs.aws.amazon.com/redshift/latest/mgmt/working-with-db-encryption.html
docs.aws.amazon.com
https://docs.aws.amazon.com/redshift/latest/gsg/getting-started.html
docs.aws.amazon.com
https://docs.aws.amazon.com/redshift/latest/mgmt/connecting-ssl-support.html
docs.aws.amazon.com
https://docs.aws.amazon.com/redshift/latest/mgmt/db-auditing.html
docs.aws.amazon.com
https://docs.aws.amazon.com/redshift/latest/APIReference/API_ModifyCluster.html
docs.aws.amazon.com
https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/domain-enable-disable-auto-renewal.html
docs.aws.amazon.com
https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/registrar-tld-list.html
docs.aws.amazon.com
https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/domain-lock.html
docs.aws.amazon.com
https://docs.aws.amazon.com/AmazonS3/latest/dev/security-best-practices.html
docs.aws.amazon.com
https://docs.aws.amazon.com/AmazonS3/latest/dev/bucket-encryption.html
docs.aws.amazon.com
https://docs.aws.amazon.com/ses/latest/DeveloperGuide/send-email-authentication-dkim.html
docs.aws.amazon.com
https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-server-side-encryption.html
docs.aws.amazon.com
https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs.html
docs.aws.amazon.com
NCC Group
www.nccgroup.trust