Research

Farksecurity.com Security Audit, August 2026

← Back to Research

I ran a full audit against my own site and infrastructure to see how it held up and to have a real example to point to. Below is the scope, the raw output where it's useful, and what got fixed as a result. Everything here reflects the current state after remediation.

Scope and method

Target was farksecurity.com and its public IP. Testing was passive and non-intrusive throughout: OSINT against public records, nmap with safe-category scripts for service and TLS enumeration, and manual checks against the application's HTTP responses. No exploitation, brute forcing, or denial of service testing was performed at any point.

  • Full Nmap Scan
  • TLS Configuration (testssl.sh)
  • HTTP Headers and Web App Hygiene
  • Vulnerability Scanning of Exposed Services
  • OSINT Recon
  • Dependencies and Supply Chain

Full Nmap Scan: Pass

Nmap scan report for farksecurity.com (209.38.7.188)
Host is up (0.051s latency).
Not shown: 997 filtered tcp ports (no-response)
PORT    STATE SERVICE
22/tcp  open  ssh
80/tcp  open  http
443/tcp open  https

Nmap done: 1 IP address (1 host up) scanned in 44.48 seconds

Three reachable services and nothing else. Everything outside SSH, HTTP, and HTTPS is filtered, so there's no forgotten dev server or exposed database sitting on some other port.

TLS Configuration (testssl.sh): Pass

#####################################################################
  testssl.sh version 3.2.4 from https://testssl.sh/

  This program is free software. Distribution and modification under
  GPLv2 permitted. USAGE w/o ANY WARRANTY. USE IT AT YOUR OWN RISK!

  Please file bugs @ https://testssl.sh/bugs/
#####################################################################

  Using OpenSSL 4.0.1 (Jun 9 2026)  [~96 ciphers]
  on [REDACTED]:/opt/homebrew/opt/openssl@4/bin/openssl

 Start 2026-08-04 13:38:26        -->> 209.38.7.188:443 (farksecurity.com) <<--

 rDNS (209.38.7.188):    --
 Service detected:       HTTP

 Testing protocols via sockets except NPN+ALPN

 SSLv2      not offered (OK)
 SSLv3      not offered (OK)
 TLS 1      not offered
 TLS 1.1    not offered
 TLS 1.2    offered (OK)
 TLS 1.3    offered (OK): final
 NPN/SPDY   not offered
 ALPN/HTTP2 http/1.1 (offered)

 Testing cipher categories

 NULL ciphers (no encryption)                      not offered (OK)
 Anonymous NULL Ciphers (no authentication)        not offered (OK)
 Export ciphers (w/o ADH+NULL)                     not offered (OK)
 LOW: 64 Bit + DES, RC[2,4], MD5 (w/o export)      not offered (OK)
 Triple DES Ciphers / IDEA                         not offered
 Obsoleted CBC ciphers (AES, ARIA etc.)            not offered
 Strong encryption (AEAD ciphers) with no FS       not offered
 Forward Secrecy strong encryption (AEAD ciphers)  offered (OK)


 Testing server's cipher preferences

Hexcode  Cipher Suite Name (OpenSSL)       KeyExch.   Encryption  Bits     Cipher Suite Name (IANA/RFC)
-----------------------------------------------------------------------------------------------------------------------------
SSLv2
 -
SSLv3
 -
TLSv1
 -
TLSv1.1
 -
TLSv1.2 (no server order, thus listed by strength)
 xc02c   ECDHE-ECDSA-AES256-GCM-SHA384     ECDH 253   AESGCM      256      TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
 xcca9   ECDHE-ECDSA-CHACHA20-POLY1305     ECDH 253   ChaCha20    256      TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256
 xc02b   ECDHE-ECDSA-AES128-GCM-SHA256     ECDH 253   AESGCM      128      TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
TLSv1.3 (no server order, thus listed by strength)
 x1302   TLS_AES_256_GCM_SHA384            ECDH 253   AESGCM      256      TLS_AES_256_GCM_SHA384
 x1303   TLS_CHACHA20_POLY1305_SHA256      ECDH 253   ChaCha20    256      TLS_CHACHA20_POLY1305_SHA256
 x1301   TLS_AES_128_GCM_SHA256            ECDH 253   AESGCM      128      TLS_AES_128_GCM_SHA256

 Has server cipher order?     no
 (limited sense as client will pick)

 Testing robust forward secrecy (FS) -- omitting Null Authentication/Encryption, 3DES, RC4

 FS is offered (OK)           TLS_AES_256_GCM_SHA384 TLS_CHACHA20_POLY1305_SHA256
                              ECDHE-ECDSA-AES256-GCM-SHA384 ECDHE-ECDSA-CHACHA20-POLY1305
                              TLS_AES_128_GCM_SHA256 ECDHE-ECDSA-AES128-GCM-SHA256
 KEMs offered                 None
 Elliptic curves offered:     prime256v1 secp384r1 secp521r1 X25519 X448
 Finite field group:          ffdhe2048 ffdhe3072 ffdhe4096 ffdhe6144 ffdhe8192
 TLS 1.2 sig_algs offered:    ECDSA+SHA512 ECDSA+SHA384 ECDSA+SHA256 ECDSA+SHA224
 TLS 1.3 sig_algs offered:    ECDSA+SHA256

 Testing server defaults (Server Hello)

 TLS extensions (standard)    "server name/#0" "max fragment length/#1" "EC point formats/#11"
                              "application layer protocol negotiation/#16" "extended master secret/#23"
                              "supported versions/#43" "key share/#51" "renegotiation info/#65281"
 Session Ticket RFC 5077 hint no -- no lifetime advertised
 SSL Session ID support       yes
 Session Resumption           Tickets no, ID: yes
 TLS clock skew               Random values, no fingerprinting possible
 Certificate Compression      none
 Client Authentication        none
 Signature Algorithm          ECDSA with SHA384
 Server key size              EC 256 bits (curve P-256)
 Server key usage             Digital Signature
 Server extended key usage    TLS Web Server Authentication
 Serial                       05A137AC08331A011C92DDFA630FED8138E9 (OK: length 18)
 Fingerprints                 SHA1 46F8F61EB6A59E633C36E4F38C9A55DE459D9BD4
                              SHA256 AE77B33028D30E6BB5623F2A2130113E97D27C2345B58A5D4858E7679B3B2FF7
 Common Name (CN)             farksecurity.com
 subjectAltName (SAN)         farksecurity.com www.farksecurity.com
 Trust (hostname)             Ok via SAN and CN (same w/o SNI)
 Chain of trust               Ok
 EV cert (experimental)       no
 Certificate Validity (UTC)   88 >= 30 days (2026-08-03 01:43 --> 2026-11-01 01:42)
 ETS/"eTLS", visibility info  not present
 Certificate Revocation List  http://ye1.c.lencr.org/106.crl
 OCSP URI                     --
 OCSP stapling                not offered
 OCSP must staple extension   --
 DNS CAA RR (experimental)    not offered
 Certificate Transparency     yes (certificate extension)
 Certificates provided        4
 Issuer                       YE1 (Let's Encrypt from US)
 Intermediate cert validity   #1: ok > 40 days (2028-09-02 23:59). YE1 <-- Root YE
                              #2: ok > 40 days (2032-09-02 23:59). Root YE <-- ISRG Root X2
                              #3: ok > 40 days (2032-09-02 23:59). ISRG Root X2 <-- ISRG Root X1
 Intermediate Bad OCSP (exp.) Ok


 Testing HTTP header response @ "/"

 HTTP Status Code             200 OK
 HTTP clock skew              0 sec from localtime
 Strict Transport Security    not offered
 Public Key Pinning           --
 Server banner                nginx/1.24.0 (Ubuntu)
 Application banner           X-Powered-By: Express
 Cookie(s)                    (none issued at "/")
 Security headers             --
 Reverse Proxy banner         --


 Testing vulnerabilities

 Heartbleed (CVE-2014-0160)                not vulnerable (OK), no heartbeat extension
 CCS (CVE-2014-0224)                       not vulnerable (OK)
 Ticketbleed (CVE-2016-9244), experiment.  not vulnerable (OK), no session ticket extension
 ROBOT                                     Server does not support any cipher suites that use RSA key transport
 Secure Renegotiation (RFC 5746)           supported (OK)
 Secure Client-Initiated Renegotiation     not vulnerable (OK)
 CRIME, TLS (CVE-2012-4929)                not vulnerable (OK)
 BREACH (CVE-2013-3587)                    potentially NOT ok, "gzip" HTTP compression detected. - only supplied "/" tested
                                           Can be ignored for static pages or if no secrets in the page
 POODLE, SSL (CVE-2014-3566)               not vulnerable (OK), no SSLv3 support
 TLS_FALLBACK_SCSV (RFC 7507)              No fallback possible (OK), no protocol below TLS 1.2 offered
 SWEET32 (CVE-2016-2183, CVE-2016-6329)    not vulnerable (OK)
 FREAK (CVE-2015-0204)                     not vulnerable (OK)
 DROWN (CVE-2016-0800, CVE-2016-0703)      not vulnerable on this host and port (OK)
                                           no RSA certificate, thus certificate can't be used with SSLv2 elsewhere
 LOGJAM (CVE-2015-4000), experimental      not vulnerable (OK): no DH EXPORT ciphers, no DH key detected with <= TLS 1.2
 BEAST (CVE-2011-3389)                     not vulnerable (OK), no SSL3 or TLS1
 LUCKY13 (CVE-2013-0169), experimental     not vulnerable (OK)
 Winshock (CVE-2014-6321), experimental    not vulnerable (OK)
 RC4 (CVE-2013-2566, CVE-2015-2808)        no RC4 ciphers detected (OK)


 Running client simulations (HTTP) via sockets

 Browser                      Protocol  Cipher Suite Name (OpenSSL)       Forward Secrecy
------------------------------------------------------------------------------------------------
 Android 7.0 (native)         TLSv1.2   ECDHE-ECDSA-AES128-GCM-SHA256     256 bit ECDH (P-256)
 Android 8.1 (native)         TLSv1.2   ECDHE-ECDSA-AES128-GCM-SHA256     253 bit ECDH (X25519)
 Android 9.0 (native)         TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 Android 10.0 (native)        TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 Android 11/12 (native)       TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 Android 13/14 (native)       TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 Android 15 (native)          TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 Chrome 101 (Win 10)          TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 Chromium 137 (Win 11)        TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 Firefox 100 (Win 10)         TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 Firefox 137 (Win 11)         TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 IE 8 Win 7                   No connection
 IE 11 Win 7                  TLSv1.2   ECDHE-ECDSA-AES256-GCM-SHA384     256 bit ECDH (P-256)
 IE 11 Win 8.1                TLSv1.2   ECDHE-ECDSA-AES256-GCM-SHA384     256 bit ECDH (P-256)
 IE 11 Win Phone 8.1          TLSv1.2   ECDHE-ECDSA-AES128-GCM-SHA256     256 bit ECDH (P-256)
 IE 11 Win 10                 TLSv1.2   ECDHE-ECDSA-AES256-GCM-SHA384     256 bit ECDH (P-256)
 Edge 15 Win 10               TLSv1.2   ECDHE-ECDSA-AES256-GCM-SHA384     253 bit ECDH (X25519)
 Edge 101 Win 10 21H2         TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 Edge 133 Win 11 23H2         TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 Safari 18.4 (iOS 18.4)       TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 Safari 15.4 (macOS 12.3.1)   TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 Safari 18.4 (macOS 15.4)     TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 Java 7u25                    No connection
 Java 8u442 (OpenJDK)         TLSv1.3   TLS_AES_256_GCM_SHA384            253 bit ECDH (X25519)
 Java 11.0.2 (OpenJDK)        TLSv1.3   TLS_AES_128_GCM_SHA256            256 bit ECDH (P-256)
 Java 17.0.3 (OpenJDK)        TLSv1.3   TLS_AES_256_GCM_SHA384            253 bit ECDH (X25519)
 Java 21.0.6 (OpenJDK)        TLSv1.3   TLS_AES_256_GCM_SHA384            253 bit ECDH (X25519)
 go 1.17.8                    TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)
 LibreSSL 3.3.6 (macOS)       TLSv1.3   TLS_CHACHA20_POLY1305_SHA256      253 bit ECDH (X25519)
 OpenSSL 1.0.2e               TLSv1.2   ECDHE-ECDSA-AES256-GCM-SHA384     256 bit ECDH (P-256)
 OpenSSL 1.1.1d (Debian)      TLSv1.3   TLS_AES_256_GCM_SHA384            253 bit ECDH (X25519)
 OpenSSL 3.0.15 (Debian)      TLSv1.3   TLS_AES_256_GCM_SHA384            253 bit ECDH (X25519)
 OpenSSL 3.5.0 (git)          TLSv1.3   TLS_AES_256_GCM_SHA384            253 bit ECDH (X25519)
 Apple Mail (16.0)            TLSv1.2   ECDHE-ECDSA-AES256-GCM-SHA384     256 bit ECDH (P-256)
 Thunderbird (91.9)           TLSv1.3   TLS_AES_128_GCM_SHA256            253 bit ECDH (X25519)


 Rating (experimental)

 Rating specs (not complete)  SSL Labs's 'SSL Server Rating Guide' (version 2009r from 2025-05-16)
 Specification documentation  https://github.com/ssllabs/research/wiki/SSL-Server-Rating-Guide
 Protocol Support (weighted)  100 (30)
 Key Exchange     (weighted)  100 (30)
 Cipher Strength  (weighted)  90 (36)
 Final Score                  96
 Overall Grade                A+

Worth pointing out that this same run is what first flagged the missing Strict Transport Security and Security headers lines near the bottom, under "Testing HTTP header response." That fed directly into the header hygiene fixes below.

HTTP Headers and Web App Hygiene

The application itself had no security header middleware in place at all. A few things stood out:

  • No Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, or Referrer-Policy on any response, matching what testssl.sh flagged above.
  • X-Powered-By: Express was disclosed on every response, handing over the backend framework for free.
  • Error responses were leaking full stack traces, including internal server file paths and the dependency tree, on any invalid route or malformed request. The production error handler was supposed to suppress this but wasn't doing so correctly.

Fixes: added helmet middleware with a content security policy scoped to what the site actually loads (its own assets and Google Fonts, plus the two external calls the Minecraft status checker page makes), enabled HSTS, disabled X-Powered-By, and corrected the production error handling so stack traces no longer render to the client. Re-verified after the fix and confirmed a clean header set with no leakage on both normal and error responses.

Vulnerability Scanning of Exposed Services

The nmap results above already cover most of this: three services reachable, everything else filtered. Digging into those three:

  • SSH was already in solid shape: key-only authentication, no password login exposed to brute force, modern key exchange and host key algorithms.
  • One smaller finding: the server still offered legacy SHA-1 based MAC algorithms (hmac-sha1, hmac-sha1-etm) alongside the modern set. Not practically exploitable on its own, but no reason to keep offering weaker options. Trimmed the MACs list in the SSH server config down to SHA-2 and UMAC variants only.
  • nginx and the reverse proxy setup showed no directory listing, blocked the TRACE method, and didn't reflect arbitrary CORS origins.

OSINT Recon

Passive recon against public records (WHOIS, DNS, certificate transparency) turned up a few gaps that don't show up unless someone goes looking:

  • No CAA record, meaning any publicly trusted certificate authority could have issued a certificate for the domain.
  • DNSSEC was unsigned at the time of the initial pass.

All are fixed now: a CAA record restricts issuance to the current certificate authority, and DNSSEC signing is enabled and verified working.

WHOIS itself was clean throughout: no registrant contact information exposed at the registry level.

Dependencies and Supply Chain: Pass

npm audit now shows 0 vulnerabilities after migrating the codebase from Jade to Pug. Jade is deprecated and carried several vulnerabilities that couldn't be resolved through npm audit fix, even with the --force flag, since the fixes only exist in Pug, its maintained successor.

Summary

Area Status
Nmap port scan Pass
TLS configuration Pass (A+)
HTTP security headers Fixed
Verbose error / stack trace disclosure Fixed
SSH hardening Fixed
CAA record Fixed
DNSSEC Fixed
Dependency vulnerabilities Pass (0 known)

Nothing here was catastrophic going in, but the gaps were exactly the kind that don't show up unless you actually go looking for them: missing headers, missing DNS policy records, and one error handler that wasn't behaving the way it was supposed to in production. That's usually where the real findings are.