═══════════════════════════════════════════════════════ Target: https://www.drejtesia.gov.al/ Status: 200 | Time: 1213ms | Issues: 12 🟠 [HIGH] MITM / Downgrade: Missing HSTS header (HTTPS downgrade possible) 🟡 [MEDIUM] Clickjacking: Missing X-Frame-Options header 🟡 [MEDIUM] XSS / Injection: Missing Content-Security-Policy header 🟡 [MEDIUM] Cookie: Cookie 'visid_incap_2808661' missing Secure flag 🟡 [MEDIUM] Cookie: Cookie 'incap_ses_2109_2808661' missing Secure flag 🟡 [MEDIUM] Cookie: Cookie 'incap_ses_2109_2808661' missing HttpOnly flag 🔵 [LOW] MIME Sniffing: Missing X-Content-Type-Options header 🔵 [LOW] Privacy: Missing Referrer-Policy header 🔵 [LOW] Feature Policy: Missing Permissions-Policy header 🔵 [LOW] XSS: Missing X-XSS-Protection header (legacy browsers) 🔵 [LOW] Cookie: Cookie 'visid_incap_2808661' missing SameSite attribute 🔵 [LOW] Cookie: Cookie 'incap_ses_2109_2808661' missing SameSite attribute ═══════════════════════════════════════════════════════ Target: https://financa.gov.al/ Status: 200 | Time: 1199ms | Issues: 12 🟠 [HIGH] MITM / Downgrade: Missing HSTS header (HTTPS downgrade possible) 🟡 [MEDIUM] Clickjacking: Missing X-Frame-Options header 🟡 [MEDIUM] XSS / Injection: Missing Content-Security-Policy header 🟡 [MEDIUM] Cookie: Cookie 'visid_incap_2808662' missing Secure flag 🟡 [MEDIUM] Cookie: Cookie 'incap_ses_79_2808662' missing Secure flag 🟡 [MEDIUM] Cookie: Cookie 'incap_ses_79_2808662' missing HttpOnly flag 🔵 [LOW] MIME Sniffing: Missing X-Content-Type-Options header 🔵 [LOW] Privacy: Missing Referrer-Policy header 🔵 [LOW] Feature Policy: Missing Permissions-Policy header 🔵 [LOW] XSS: Missing X-XSS-Protection header (legacy browsers) 🔵 [LOW] Cookie: Cookie 'visid_incap_2808662' missing SameSite attribute 🔵 [LOW] Cookie: Cookie 'incap_ses_79_2808662' missing SameSite attribute ═══════════════════════════════════════════════════════ Target: https://arsimi.gov.al/ Status: 200 | Time: 1501ms | Issues: 12 🟠 [HIGH] MITM / Downgrade: Missing HSTS header (HTTPS downgrade possible) 🟡 [MEDIUM] Clickjacking: Missing X-Frame-Options header 🟡 [MEDIUM] XSS / Injection: Missing Content-Security-Policy header 🟡 [MEDIUM] Cookie: Cookie 'visid_incap_2808659' missing Secure flag 🟡 [MEDIUM] Cookie: Cookie 'incap_ses_577_2808659' missing Secure flag 🟡 [MEDIUM] Cookie: Cookie 'incap_ses_577_2808659' missing HttpOnly flag 🔵 [LOW] MIME Sniffing: Missing X-Content-Type-Options header 🔵 [LOW] Privacy: Missing Referrer-Policy header 🔵 [LOW] Feature Policy: Missing Permissions-Policy header 🔵 [LOW] XSS: Missing X-XSS-Protection header (legacy browsers) 🔵 [LOW] Cookie: Cookie 'visid_incap_2808659' missing SameSite attribute 🔵 [LOW] Cookie: Cookie 'incap_ses_577_2808659' missing SameSite attribute ═══════════════════════════════════════════════════════ Target: https://akshi.gov.al Status: 200 | Time: 2569ms | Issues: 7 Redirected to: https://akshi.gov.al/ 🟡 [MEDIUM] Clickjacking: Missing X-Frame-Options header 🟡 [MEDIUM] XSS / Injection: Missing Content-Security-Policy header 🔵 [LOW] MIME Sniffing: Missing X-Content-Type-Options header 🔵 [LOW] Privacy: Missing Referrer-Policy header 🔵 [LOW] Feature Policy: Missing Permissions-Policy header 🔵 [LOW] XSS: Missing X-XSS-Protection header (legacy browsers) 🔵 [LOW] Info Disclosure: Server header exposed: nginx/1.19.10 ═══════════════════════════════════════════════════════ Target: https://www.infrastruktura.gov.al/ Status: 200 | Time: 1151ms | Issues: 12 🟠 [HIGH] MITM / Downgrade: Missing HSTS header (HTTPS downgrade possible) 🟡 [MEDIUM] Clickjacking: Missing X-Frame-Options header 🟡 [MEDIUM] XSS / Injection: Missing Content-Security-Policy header 🟡 [MEDIUM] Cookie: Cookie 'visid_incap_2808663' missing Secure flag 🟡 [MEDIUM] Cookie: Cookie 'incap_ses_2109_2808663' missing Secure flag 🟡 [MEDIUM] Cookie: Cookie 'incap_ses_2109_2808663' missing HttpOnly flag 🔵 [LOW] MIME Sniffing: Missing X-Content-Type-Options header 🔵 [LOW] Privacy: Missing Referrer-Policy header 🔵 [LOW] Feature Policy: Missing Permissions-Policy header 🔵 [LOW] XSS: Missing X-XSS-Protection header (legacy browsers) 🔵 [LOW] Cookie: Cookie 'visid_incap_2808663' missing SameSite attribute 🔵 [LOW] Cookie: Cookie 'incap_ses_2109_2808663' missing SameSite attribute ═══════════════════════════════════════════════════════ Target: https://mapa.gov.al/ Status: 200 | Time: 1918ms | Issues: 11 🟠 [HIGH] MITM / Downgrade: Missing HSTS header (HTTPS downgrade possible) 🟡 [MEDIUM] XSS / Injection: Missing Content-Security-Policy header 🟡 [MEDIUM] Cookie: Cookie 'visid_incap_3161924' missing Secure flag 🟡 [MEDIUM] Cookie: Cookie 'incap_ses_79_3161924' missing Secure flag 🟡 [MEDIUM] Cookie: Cookie 'incap_ses_79_3161924' missing HttpOnly flag 🔵 [LOW] Privacy: Missing Referrer-Policy header 🔵 [LOW] Feature Policy: Missing Permissions-Policy header 🔵 [LOW] XSS: Missing X-XSS-Protection header (legacy browsers) 🔵 [LOW] Info Disclosure: Server header exposed: nginx 🔵 [LOW] Cookie: Cookie 'visid_incap_3161924' missing SameSite attribute 🔵 [LOW] Cookie: Cookie 'incap_ses_79_3161924' missing SameSite attribute ═══════════════════════════════════════════════════════ Target: https://www.mod.gov.al/ Status: 200 | Time: 3505ms | Issues: 13 🟠 [HIGH] MITM / Downgrade: Missing HSTS header (HTTPS downgrade possible) 🟡 [MEDIUM] Clickjacking: Missing X-Frame-Options header 🟡 [MEDIUM] XSS / Injection: Missing Content-Security-Policy header 🟡 [MEDIUM] Cookie: Cookie 'a3c18a1c35d02e7a37c5886b45f8bfa6' missing Secure flag 🟡 [MEDIUM] Info Disclosure: Exception message in response 🟡 [MEDIUM] Info Disclosure: Syntax error in response — possible code leak 🔵 [LOW] MIME Sniffing: Missing X-Content-Type-Options header 🔵 [LOW] Privacy: Missing Referrer-Policy header 🔵 [LOW] Feature Policy: Missing Permissions-Policy header 🔵 [LOW] XSS: Missing X-XSS-Protection header (legacy browsers) 🔵 [LOW] Info Disclosure: Server header exposed: Apache 🔵 [LOW] Cookie: Cookie 'a3c18a1c35d02e7a37c5886b45f8bfa6' missing SameSite attribute 🔵 [LOW] Info Disclosure: Keyword 'password' found in response body ═══════════════════════════════════════════════════════ Target: https://asp.gov.al/ Status: 200 | Time: 1985ms | Issues: 9 🟠 [HIGH] MITM / Downgrade: Missing HSTS header (HTTPS downgrade possible) 🟡 [MEDIUM] Clickjacking: Missing X-Frame-Options header 🟡 [MEDIUM] XSS / Injection: Missing Content-Security-Policy header 🟡 [MEDIUM] SSL: Certificate expires in 19 days 🔵 [LOW] MIME Sniffing: Missing X-Content-Type-Options header 🔵 [LOW] Privacy: Missing Referrer-Policy header 🔵 [LOW] Feature Policy: Missing Permissions-Policy header 🔵 [LOW] XSS: Missing X-XSS-Protection header (legacy browsers) 🔵 [LOW] Info Disclosure: Server header exposed: Apache ═══════════════════════════════════════════════════════ Target: https://shendetesia.gov.al/ Status: 200 | Time: 1088ms | Issues: 12 🟠 [HIGH] MITM / Downgrade: Missing HSTS header (HTTPS downgrade possible) 🟡 [MEDIUM] Clickjacking: Missing X-Frame-Options header 🟡 [MEDIUM] XSS / Injection: Missing Content-Security-Policy header 🟡 [MEDIUM] Cookie: Cookie 'visid_incap_2808671' missing Secure flag 🟡 [MEDIUM] Cookie: Cookie 'incap_ses_79_2808671' missing Secure flag 🟡 [MEDIUM] Cookie: Cookie 'incap_ses_79_2808671' missing HttpOnly flag 🔵 [LOW] MIME Sniffing: Missing X-Content-Type-Options header 🔵 [LOW] Privacy: Missing Referrer-Policy header 🔵 [LOW] Feature Policy: Missing Permissions-Policy header 🔵 [LOW] XSS: Missing X-XSS-Protection header (legacy browsers) 🔵 [LOW] Cookie: Cookie 'visid_incap_2808671' missing SameSite attribute 🔵 [LOW] Cookie: Cookie 'incap_ses_79_2808671' missing SameSite attribute ═══════════════════════════════════════════════════════ Target: https://arkiva.shendetesia.gov.al ✗ Error: SSL Error: HTTPSConnectionPool(host='arkiva.shendetesia.gov.al', port=443): Max retries exceeded with url: / (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1000)'))) ═══════════════════════════════════════════════════════ Target: https://mjedisi.gov.al/ Status: 200 | Time: 1921ms | Issues: 13 🟠 [HIGH] MITM / Downgrade: Missing HSTS header (HTTPS downgrade possible) 🟡 [MEDIUM] Clickjacking: Missing X-Frame-Options header 🟡 [MEDIUM] XSS / Injection: Missing Content-Security-Policy header 🟡 [MEDIUM] Cookie: Cookie 'visid_incap_3261576' missing Secure flag 🟡 [MEDIUM] Cookie: Cookie 'incap_ses_79_3261576' missing Secure flag 🟡 [MEDIUM] Cookie: Cookie 'incap_ses_79_3261576' missing HttpOnly flag 🔵 [LOW] MIME Sniffing: Missing X-Content-Type-Options header 🔵 [LOW] Privacy: Missing Referrer-Policy header 🔵 [LOW] Feature Policy: Missing Permissions-Policy header 🔵 [LOW] XSS: Missing X-XSS-Protection header (legacy browsers) 🔵 [LOW] Info Disclosure: Server header exposed: nginx 🔵 [LOW] Cookie: Cookie 'visid_incap_3261576' missing SameSite attribute 🔵 [LOW] Cookie: Cookie 'incap_ses_79_3261576' missing SameSite attribute ═══════════════════════════════════════════════════════ Target: https://mash.rks-gov.net/ Status: 200 | Time: 2337ms | Issues: 5 🟡 [MEDIUM] Info Disclosure: Exception message in response 🔵 [LOW] XSS: Missing X-XSS-Protection header (legacy browsers) 🔵 [LOW] Info Disclosure: Server header exposed: nginx 🔵 [LOW] Info Disclosure: X-Powered-By header exposed: PHP/8.3.30, PleskLin 🔵 [LOW] Info Disclosure: Keyword 'password' found in response body ═══════════════════════════════════════════════════════ Target: https://www.mod.gov.al/ Status: 200 | Time: 3436ms | Issues: 13 🟠 [HIGH] MITM / Downgrade: Missing HSTS header (HTTPS downgrade possible) 🟡 [MEDIUM] Clickjacking: Missing X-Frame-Options header 🟡 [MEDIUM] XSS / Injection: Missing Content-Security-Policy header 🟡 [MEDIUM] Cookie: Cookie 'a3c18a1c35d02e7a37c5886b45f8bfa6' missing Secure flag 🟡 [MEDIUM] Info Disclosure: Exception message in response 🟡 [MEDIUM] Info Disclosure: Syntax error in response — possible code leak 🔵 [LOW] MIME Sniffing: Missing X-Content-Type-Options header 🔵 [LOW] Privacy: Missing Referrer-Policy header 🔵 [LOW] Feature Policy: Missing Permissions-Policy header 🔵 [LOW] XSS: Missing X-XSS-Protection header (legacy browsers) 🔵 [LOW] Info Disclosure: Server header exposed: Apache 🔵 [LOW] Cookie: Cookie 'a3c18a1c35d02e7a37c5886b45f8bfa6' missing SameSite attribute 🔵 [LOW] Info Disclosure: Keyword 'password' found in response body ═══════════════════════════════════════════════════════ Target: https://e-albania.al/ ✗ Error: ('Connection aborted.', ConnectionResetError(104, 'Connection reset by peer')) ═══════════════════════════════════════════════════════ Scan Summary Targets scanned : 14 Errors : 2 Total issues : 131 CRITICAL : 0 HIGH : 10 MEDIUM : 50 LOW : 71 INFO : 0 cia@nsa:~/Desktop$