Date: February 9, 2026 17:14 UTC
Scanner: Bounty Hunt CLI v3.0 (Phase 3)
Overall Risk Score: 45/100 (MEDIUM)
| Subdomain | Risk Level | Notes |
|---|---|---|
| arielfuggini.com | - | Main domain |
| blog.arielfuggini.com | Low | Blog subdomain |
| marketing.arielfuggini.com | Low | Marketing subdomain |
| v2.arielfuggini.com | Staging/dev version |
| Provider | Status |
|---|---|
| AWS S3 | β No exposure |
| Azure Blob | β No exposure |
| Google Cloud | β No exposure |
| DigitalOcean | β No exposure |
Risk Score: 0/100 β
| Check | Result |
|---|---|
| Issuer | Let's Encrypt (WE1) |
| Valid Until | Apr 27, 2026 |
| Days Remaining | 77 |
| Expired | No |
| Vulnerabilities | None |
Risk Score: 20/100 β
| Protocol | Status | Issue |
|---|---|---|
| SPF | β Missing | Domain vulnerable to email spoofing |
| DKIM | β Missing | Email authenticity cannot be verified |
| DMARC | β Missing | Cannot enforce email policies |
Risk Score: 75/100 π΄ CRITICAL
| Method | Status |
|---|---|
| GET | β Allowed |
| HEAD | β Allowed |
| OPTIONS | β Allowed |
| CONNECT |
Issue: CONNECT allows tunneling (proxy abuse)
Risk Score: 25/100 π MEDIUM
| Check | Status | Risk |
|---|---|---|
| CORS Misconfiguration | β Not enabled | 0/100 |
| Directory Listing | β Protected | 0/100 |
| Subdomain Takeover | β Not vulnerable | 0/100 |
| Open Redirect | β Not vulnerable | 0/100 |
1. Email Authentication Missing
Impact: Domain can be spoofed for phishing attacks
Fix: Add DNS TXT records:
SPF: v=spf1 include:_spf.google.com ~all
DMARC: v=DMARC1; p=quarantine; rua=mailto:dmarc@arielfuggini.com
2. High-Value Subdomain: v2.arielfuggini.com
Impact: Potential staging environment with weaker security
Fix: Review access controls, ensure production-level security
1. HTTP CONNECT Method Enabled
Impact: Potential proxy abuse
Fix: Disable in web server configuration
- SSL certificate valid
- No cloud bucket exposure
- No CORS vulnerabilities
- No directory listing
- No subdomain takeover risk
- No open redirect vulnerabilities
| # | Issue | Effort | Impact |
|---|---|---|---|
| 1 | Configure SPF/DKIM/DMARC | 15 min | Critical |
| 2 | Review v2.arielfuggini.com | 30 min | High |
| 3 | Disable CONNECT method | 5 min | Medium |
- Modules Used: 11 security scanners
- Subdomains Tested: 4
- Cloud Providers Checked: 4
- Total Scan Time: ~45 seconds
Tool: https://github.com/ArielFuggini/bounty-hunter
Generated by Bounty Hunt CLI - For authorized security research only π‘οΈ