I ran a full audit against my own site and infrastructure to see how it held up and to have a real example to point to. Below is the scope, the raw output where it's useful, and what got fixed as a result. Everything here reflects the current state after remediation.
Scope and method
Target was farksecurity.com and its public IP. Testing was passive and non-intrusive throughout: OSINT against public records, nmap with safe-category scripts for service and TLS enumeration, and manual checks against the application's HTTP responses. No exploitation, brute forcing, or denial of service testing was performed at any point.
- Full Nmap Scan
- TLS Configuration (testssl.sh)
- HTTP Headers and Web App Hygiene
- Vulnerability Scanning of Exposed Services
- OSINT Recon
- Dependencies and Supply Chain
Full Nmap Scan: Pass
Nmap scan report for farksecurity.com (209.38.7.188)
Host is up (0.051s latency).
Not shown: 997 filtered tcp ports (no-response)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
443/tcp open https
Nmap done: 1 IP address (1 host up) scanned in 44.48 seconds
Three reachable services and nothing else. Everything outside SSH, HTTP, and HTTPS is filtered, so there's no forgotten dev server or exposed database sitting on some other port.
TLS Configuration (testssl.sh): Pass
#####################################################################
testssl.sh version 3.2.4 from https://testssl.sh/
This program is free software. Distribution and modification under
GPLv2 permitted. USAGE w/o ANY WARRANTY. USE IT AT YOUR OWN RISK!
Please file bugs @ https://testssl.sh/bugs/
#####################################################################
Using OpenSSL 4.0.1 (Jun 9 2026) [~96 ciphers]
on [REDACTED]:/opt/homebrew/opt/openssl@4/bin/openssl
Start 2026-08-04 13:38:26 -->> 209.38.7.188:443 (farksecurity.com) <<--
rDNS (209.38.7.188): --
Service detected: HTTP
Testing protocols via sockets except NPN+ALPN
SSLv2 not offered (OK)
SSLv3 not offered (OK)
TLS 1 not offered
TLS 1.1 not offered
TLS 1.2 offered (OK)
TLS 1.3 offered (OK): final
NPN/SPDY not offered
ALPN/HTTP2 http/1.1 (offered)
Testing cipher categories
NULL ciphers (no encryption) not offered (OK)
Anonymous NULL Ciphers (no authentication) not offered (OK)
Export ciphers (w/o ADH+NULL) not offered (OK)
LOW: 64 Bit + DES, RC[2,4], MD5 (w/o export) not offered (OK)
Triple DES Ciphers / IDEA not offered
Obsoleted CBC ciphers (AES, ARIA etc.) not offered
Strong encryption (AEAD ciphers) with no FS not offered
Forward Secrecy strong encryption (AEAD ciphers) offered (OK)
Testing server's cipher preferences
Hexcode Cipher Suite Name (OpenSSL) KeyExch. Encryption Bits Cipher Suite Name (IANA/RFC)
-----------------------------------------------------------------------------------------------------------------------------
SSLv2
-
SSLv3
-
TLSv1
-
TLSv1.1
-
TLSv1.2 (no server order, thus listed by strength)
xc02c ECDHE-ECDSA-AES256-GCM-SHA384 ECDH 253 AESGCM 256 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
xcca9 ECDHE-ECDSA-CHACHA20-POLY1305 ECDH 253 ChaCha20 256 TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256
xc02b ECDHE-ECDSA-AES128-GCM-SHA256 ECDH 253 AESGCM 128 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
TLSv1.3 (no server order, thus listed by strength)
x1302 TLS_AES_256_GCM_SHA384 ECDH 253 AESGCM 256 TLS_AES_256_GCM_SHA384
x1303 TLS_CHACHA20_POLY1305_SHA256 ECDH 253 ChaCha20 256 TLS_CHACHA20_POLY1305_SHA256
x1301 TLS_AES_128_GCM_SHA256 ECDH 253 AESGCM 128 TLS_AES_128_GCM_SHA256
Has server cipher order? no
(limited sense as client will pick)
Testing robust forward secrecy (FS) -- omitting Null Authentication/Encryption, 3DES, RC4
FS is offered (OK) TLS_AES_256_GCM_SHA384 TLS_CHACHA20_POLY1305_SHA256
ECDHE-ECDSA-AES256-GCM-SHA384 ECDHE-ECDSA-CHACHA20-POLY1305
TLS_AES_128_GCM_SHA256 ECDHE-ECDSA-AES128-GCM-SHA256
KEMs offered None
Elliptic curves offered: prime256v1 secp384r1 secp521r1 X25519 X448
Finite field group: ffdhe2048 ffdhe3072 ffdhe4096 ffdhe6144 ffdhe8192
TLS 1.2 sig_algs offered: ECDSA+SHA512 ECDSA+SHA384 ECDSA+SHA256 ECDSA+SHA224
TLS 1.3 sig_algs offered: ECDSA+SHA256
Testing server defaults (Server Hello)
TLS extensions (standard) "server name/#0" "max fragment length/#1" "EC point formats/#11"
"application layer protocol negotiation/#16" "extended master secret/#23"
"supported versions/#43" "key share/#51" "renegotiation info/#65281"
Session Ticket RFC 5077 hint no -- no lifetime advertised
SSL Session ID support yes
Session Resumption Tickets no, ID: yes
TLS clock skew Random values, no fingerprinting possible
Certificate Compression none
Client Authentication none
Signature Algorithm ECDSA with SHA384
Server key size EC 256 bits (curve P-256)
Server key usage Digital Signature
Server extended key usage TLS Web Server Authentication
Serial 05A137AC08331A011C92DDFA630FED8138E9 (OK: length 18)
Fingerprints SHA1 46F8F61EB6A59E633C36E4F38C9A55DE459D9BD4
SHA256 AE77B33028D30E6BB5623F2A2130113E97D27C2345B58A5D4858E7679B3B2FF7
Common Name (CN) farksecurity.com
subjectAltName (SAN) farksecurity.com www.farksecurity.com
Trust (hostname) Ok via SAN and CN (same w/o SNI)
Chain of trust Ok
EV cert (experimental) no
Certificate Validity (UTC) 88 >= 30 days (2026-08-03 01:43 --> 2026-11-01 01:42)
ETS/"eTLS", visibility info not present
Certificate Revocation List http://ye1.c.lencr.org/106.crl
OCSP URI --
OCSP stapling not offered
OCSP must staple extension --
DNS CAA RR (experimental) not offered
Certificate Transparency yes (certificate extension)
Certificates provided 4
Issuer YE1 (Let's Encrypt from US)
Intermediate cert validity #1: ok > 40 days (2028-09-02 23:59). YE1 <-- Root YE
#2: ok > 40 days (2032-09-02 23:59). Root YE <-- ISRG Root X2
#3: ok > 40 days (2032-09-02 23:59). ISRG Root X2 <-- ISRG Root X1
Intermediate Bad OCSP (exp.) Ok
Testing HTTP header response @ "/"
HTTP Status Code 200 OK
HTTP clock skew 0 sec from localtime
Strict Transport Security not offered
Public Key Pinning --
Server banner nginx/1.24.0 (Ubuntu)
Application banner X-Powered-By: Express
Cookie(s) (none issued at "/")
Security headers --
Reverse Proxy banner --
Testing vulnerabilities
Heartbleed (CVE-2014-0160) not vulnerable (OK), no heartbeat extension
CCS (CVE-2014-0224) not vulnerable (OK)
Ticketbleed (CVE-2016-9244), experiment. not vulnerable (OK), no session ticket extension
ROBOT Server does not support any cipher suites that use RSA key transport
Secure Renegotiation (RFC 5746) supported (OK)
Secure Client-Initiated Renegotiation not vulnerable (OK)
CRIME, TLS (CVE-2012-4929) not vulnerable (OK)
BREACH (CVE-2013-3587) potentially NOT ok, "gzip" HTTP compression detected. - only supplied "/" tested
Can be ignored for static pages or if no secrets in the page
POODLE, SSL (CVE-2014-3566) not vulnerable (OK), no SSLv3 support
TLS_FALLBACK_SCSV (RFC 7507) No fallback possible (OK), no protocol below TLS 1.2 offered
SWEET32 (CVE-2016-2183, CVE-2016-6329) not vulnerable (OK)
FREAK (CVE-2015-0204) not vulnerable (OK)
DROWN (CVE-2016-0800, CVE-2016-0703) not vulnerable on this host and port (OK)
no RSA certificate, thus certificate can't be used with SSLv2 elsewhere
LOGJAM (CVE-2015-4000), experimental not vulnerable (OK): no DH EXPORT ciphers, no DH key detected with <= TLS 1.2
BEAST (CVE-2011-3389) not vulnerable (OK), no SSL3 or TLS1
LUCKY13 (CVE-2013-0169), experimental not vulnerable (OK)
Winshock (CVE-2014-6321), experimental not vulnerable (OK)
RC4 (CVE-2013-2566, CVE-2015-2808) no RC4 ciphers detected (OK)
Running client simulations (HTTP) via sockets
Browser Protocol Cipher Suite Name (OpenSSL) Forward Secrecy
------------------------------------------------------------------------------------------------
Android 7.0 (native) TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256 256 bit ECDH (P-256)
Android 8.1 (native) TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256 253 bit ECDH (X25519)
Android 9.0 (native) TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
Android 10.0 (native) TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
Android 11/12 (native) TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
Android 13/14 (native) TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
Android 15 (native) TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
Chrome 101 (Win 10) TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
Chromium 137 (Win 11) TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
Firefox 100 (Win 10) TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
Firefox 137 (Win 11) TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
IE 8 Win 7 No connection
IE 11 Win 7 TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384 256 bit ECDH (P-256)
IE 11 Win 8.1 TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384 256 bit ECDH (P-256)
IE 11 Win Phone 8.1 TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256 256 bit ECDH (P-256)
IE 11 Win 10 TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384 256 bit ECDH (P-256)
Edge 15 Win 10 TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384 253 bit ECDH (X25519)
Edge 101 Win 10 21H2 TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
Edge 133 Win 11 23H2 TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
Safari 18.4 (iOS 18.4) TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
Safari 15.4 (macOS 12.3.1) TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
Safari 18.4 (macOS 15.4) TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
Java 7u25 No connection
Java 8u442 (OpenJDK) TLSv1.3 TLS_AES_256_GCM_SHA384 253 bit ECDH (X25519)
Java 11.0.2 (OpenJDK) TLSv1.3 TLS_AES_128_GCM_SHA256 256 bit ECDH (P-256)
Java 17.0.3 (OpenJDK) TLSv1.3 TLS_AES_256_GCM_SHA384 253 bit ECDH (X25519)
Java 21.0.6 (OpenJDK) TLSv1.3 TLS_AES_256_GCM_SHA384 253 bit ECDH (X25519)
go 1.17.8 TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
LibreSSL 3.3.6 (macOS) TLSv1.3 TLS_CHACHA20_POLY1305_SHA256 253 bit ECDH (X25519)
OpenSSL 1.0.2e TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384 256 bit ECDH (P-256)
OpenSSL 1.1.1d (Debian) TLSv1.3 TLS_AES_256_GCM_SHA384 253 bit ECDH (X25519)
OpenSSL 3.0.15 (Debian) TLSv1.3 TLS_AES_256_GCM_SHA384 253 bit ECDH (X25519)
OpenSSL 3.5.0 (git) TLSv1.3 TLS_AES_256_GCM_SHA384 253 bit ECDH (X25519)
Apple Mail (16.0) TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384 256 bit ECDH (P-256)
Thunderbird (91.9) TLSv1.3 TLS_AES_128_GCM_SHA256 253 bit ECDH (X25519)
Rating (experimental)
Rating specs (not complete) SSL Labs's 'SSL Server Rating Guide' (version 2009r from 2025-05-16)
Specification documentation https://github.com/ssllabs/research/wiki/SSL-Server-Rating-Guide
Protocol Support (weighted) 100 (30)
Key Exchange (weighted) 100 (30)
Cipher Strength (weighted) 90 (36)
Final Score 96
Overall Grade A+
Worth pointing out that this same run is what first flagged the missing Strict Transport Security and Security headers lines near the bottom, under "Testing HTTP header response." That fed directly into the header hygiene fixes below.
HTTP Headers and Web App Hygiene
The application itself had no security header middleware in place at all. A few things stood out:
- No
Strict-Transport-Security,Content-Security-Policy,X-Frame-Options,X-Content-Type-Options, orReferrer-Policyon any response, matching what testssl.sh flagged above. X-Powered-By: Expresswas disclosed on every response, handing over the backend framework for free.- Error responses were leaking full stack traces, including internal server file paths and the dependency tree, on any invalid route or malformed request. The production error handler was supposed to suppress this but wasn't doing so correctly.
Fixes: added helmet middleware with a content security policy scoped to what the site actually loads (its own assets and Google Fonts, plus the two external calls the Minecraft status checker page makes), enabled HSTS, disabled X-Powered-By, and corrected the production error handling so stack traces no longer render to the client. Re-verified after the fix and confirmed a clean header set with no leakage on both normal and error responses.
Vulnerability Scanning of Exposed Services
The nmap results above already cover most of this: three services reachable, everything else filtered. Digging into those three:
- SSH was already in solid shape: key-only authentication, no password login exposed to brute force, modern key exchange and host key algorithms.
- One smaller finding: the server still offered legacy SHA-1 based MAC algorithms (
hmac-sha1,hmac-sha1-etm) alongside the modern set. Not practically exploitable on its own, but no reason to keep offering weaker options. Trimmed theMACslist in the SSH server config down to SHA-2 and UMAC variants only. - nginx and the reverse proxy setup showed no directory listing, blocked the
TRACEmethod, and didn't reflect arbitrary CORS origins.
OSINT Recon
Passive recon against public records (WHOIS, DNS, certificate transparency) turned up a few gaps that don't show up unless someone goes looking:
- No CAA record, meaning any publicly trusted certificate authority could have issued a certificate for the domain.
- DNSSEC was unsigned at the time of the initial pass.
All are fixed now: a CAA record restricts issuance to the current certificate authority, and DNSSEC signing is enabled and verified working.
WHOIS itself was clean throughout: no registrant contact information exposed at the registry level.
Dependencies and Supply Chain: Pass
npm audit now shows 0 vulnerabilities after migrating the codebase from Jade to Pug. Jade is deprecated and carried several vulnerabilities that couldn't be resolved through npm audit fix, even with the --force flag, since the fixes only exist in Pug, its maintained successor.
Summary
| Area | Status |
|---|---|
| Nmap port scan | Pass |
| TLS configuration | Pass (A+) |
| HTTP security headers | Fixed |
| Verbose error / stack trace disclosure | Fixed |
| SSH hardening | Fixed |
| CAA record | Fixed |
| DNSSEC | Fixed |
| Dependency vulnerabilities | Pass (0 known) |
Nothing here was catastrophic going in, but the gaps were exactly the kind that don't show up unless you actually go looking for them: missing headers, missing DNS policy records, and one error handler that wasn't behaving the way it was supposed to in production. That's usually where the real findings are.