# Security Report: h0sint.com
> Generated: 2026-08-06T13:06:24Z · Scan data as of: 2026-08-06T10:16:46Z

## Risk Verdict

**Overall: 🟢 Green**

The external attack surface for h0sint.com presents a Green overall risk posture. The scan detected no high-probability exploitation vectors (no CVEs with EPSS scores in the top findings) and no actively exploited vulnerabilities in CISA KEV. The two most notable findings are Missing Subresource Integrity (SRI) and GitHub Workflow Disclosure, both rated Low severity after infrastructure discounting via Cloudflare CDN. Business impact is limited to potential supply-chain script tampering (SRI) and minor CI/CD configuration exposure (workflow files) — neither enables direct system compromise. The key recommendation is to implement Subresource Integrity hashes on all third-party scripts and restrict public access to `.github/workflows/` directories.

### Risk by Category

- 🟢 **Infrastructure**: Green
- 🟢 **Security Vulnerabilities**: Green
- 🟠 **Email Security**: Amber
- 🟢 **Exposure Surface**: Green
- 🟢 **Technology Stack**: Green
- 🟢 **Supply Chain**: Green

---

## Key Metrics

| Metric | Count |
|--------|-------|
| DNS Records | 11 |
| IP Addresses | 0 |
| Open Ports | 6 |
| Vulnerabilities | 6 |
| Findings | 10 |
| Technologies | 11 |
| Emails | 3 |
| URLs | 38 |

### Severity Distribution

- 🟡 **Medium**: 2
- 🔵 **Low**: 8

---

## Vulnerabilities

| Host | Port | CVE | Severity | Description |
|------|------|-----|----------|-------------|
| h0sint.com | 443 | - | medium | [MEDIUM] template: [dockerfile-hidden-disclosure], name: [Dockerfile - Detect] |
| h0sint.com | 443 | - | medium | [MEDIUM] template: [github-workflows-disclosure], name: [Github Workflow Disclosure] |
| h0sint.com | 443 | - | medium | [MEDIUM] template: [dockerfile-hidden-disclosure], name: [Dockerfile - Detect] |
| h0sint.com | 443 | - | medium | [MEDIUM] template: [github-workflows-disclosure], name: [Github Workflow Disclosure] |
| h0sint.com | - | - | info | template: [github-workflows-disclosure], name: [Github Workflow Disclosure] |
| h0sint.com | - | - | info | template: [dockerfile-hidden-disclosure], name: [Dockerfile - Detect] |

---

## Security Findings

_10 active finding(s) after triage; 9 not re-tested by the latest scan; 20 suppressed as noise/false-positive; 1 fixed since the last scan (excluded from the count)._

| Severity | Score | Finding | Host | State | Last scan |
|----------|-------|---------|------|-------|-----------|
| Low | 2.5 | Missing Subresource Integrity (missing-sri) | tease.h0sint.com | unscreened | not re-tested |
| Medium | 1.6 | Github Workflow Disclosure (github-workflows-disclosure) | h0sint.com | unscreened | not re-tested |
| Medium | 1.6 | Dockerfile - Detect (dockerfile-hidden-disclosure) | h0sint.com | unscreened | not re-tested |
| Low | 0.8 | Email Extractor (email-extractor) | tease.h0sint.com | unscreened | not re-tested |
| Low | 0.8 | README.md file disclosure (readme-md) | tease.h0sint.com | unscreened | not re-tested |
| Low | 0.8 | RDAP WHOIS (rdap-whois) | h0sint.com | unscreened | not re-tested |
| Low | 0.8 | Google Apps (mx-service-detector) | h0sint.com | unscreened | not re-tested |
| Low | 0.8 | NPM package.json Disclosure (package-json) | h0sint.com | unscreened | not re-tested |
| Low | 0.8 | Finding | tease.h0sint.com | unscreened | — |
| Low | 0.8 | security.txt File (security-txt) | h0sint.com | unscreened | not re-tested |

### Fixed Since Last Scan

_The latest scan re-ran the detecting module over the same host and did not re-find these. They are excluded from the counts and the verdict above._

| Severity | Finding | Host | Last seen |
|----------|---------|------|-----------|
| Low | Found a Newsletter Submission Form that could be used for email bombing attacks | tease.h0sint.com | 2026-07-30 |

### Recon Signals (raw, pre-triage)

| Module | Host | Description |
|--------|------|-------------|
| newsletters | tease.h0sint.com | Found a Newsletter Submission Form that could be used for email bombing attacks |
| nuclei | tease.h0sint.com | template: [tls-version], name: [TLS Version - Detect] Extracted Data: [tls13] |
| nuclei | tease.h0sint.com | template: [tls-version], name: [TLS Version - Detect] Extracted Data: [tls12] |
| nuclei | tease.h0sint.com | template: [addeventlistener-detect], name: [Add DOM EventListener - Detection] |
| nuclei | tease.h0sint.com | template: [email-extractor], name: [Email Extractor] Extracted Data: [knowone@h0sint.com] |
| nuclei | tease.h0sint.com | template: [robots-txt-endpoint], name: [robots.txt endpoint prober] |
| nuclei | tease.h0sint.com | template: [readme-md], name: [README.md file disclosure] |
| nuclei | tease.h0sint.com | template: [missing-sri], name: [Missing Subresource Integrity] Extracted Data: [https://fonts.google |
| nuclei | tease.h0sint.com | template: [http-missing-security-headers], name: [permissions-policy] |
| nuclei | tease.h0sint.com | template: [http-missing-security-headers], name: [x-frame-options] |
| nuclei | tease.h0sint.com | template: [http-missing-security-headers], name: [x-permitted-cross-domain-policies] |
| nuclei | tease.h0sint.com | template: [robots-txt], name: [robots.txt file] |
| nuclei | tease.h0sint.com | template: [http-missing-security-headers], name: [content-security-policy] |
| nuclei | tease.h0sint.com | template: [http-missing-security-headers], name: [strict-transport-security] |
| nuclei | tease.h0sint.com | template: [http-missing-security-headers], name: [cross-origin-resource-policy] |
| nuclei | tease.h0sint.com | template: [http-missing-security-headers], name: [cross-origin-embedder-policy] |
| nuclei | tease.h0sint.com | template: [http-missing-security-headers], name: [cross-origin-opener-policy] |
| nuclei | tease.h0sint.com | template: [ssl-dns-names], name: [SSL DNS Names] Extracted Data: [tease.h0sint.com] |
| nuclei | tease.h0sint.com | template: [ssl-issuer], name: [Detect SSL Certificate Issuer] Extracted Data: [Google Trust Services |
| nuclei | tease.h0sint.com | template: [aaaa-fingerprint], name: [AAAA Record - IPv6 Detection] Extracted Data: [2606:4700:3033:: |
| nuclei | tease.h0sint.com | template: [caa-fingerprint], name: [CAA Record] |
| nuclei | tease.h0sint.com | template: [robots-txt-endpoint], name: [robots.txt endpoint prober] |
| nuclei | tease.h0sint.com | template: [robots-txt], name: [robots.txt file] |
| nuclei | tease.h0sint.com | template: [caa-fingerprint], name: [CAA Record] |
| nuclei | tease.h0sint.com | template: [aaaa-fingerprint], name: [AAAA Record - IPv6 Detection] Extracted Data: [2606:4700:3034:: |
| nuclei | tease.h0sint.com | template: [aaaa-fingerprint], name: [AAAA Record - IPv6 Detection] Extracted Data: [2606:4700:3034:: |
| nuclei | tease.h0sint.com | template: [aaaa-fingerprint], name: [AAAA Record - IPv6 Detection] Extracted Data: [2606:4700:3033:: |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [permissions-policy] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [x-permitted-cross-domain-policies] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [content-security-policy] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [cross-origin-embedder-policy] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [cross-origin-resource-policy] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [x-frame-options] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [strict-transport-security] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [cross-origin-opener-policy] |
| nuclei | h0sint.com | template: [robots-txt-endpoint], name: [robots.txt endpoint prober] |
| nuclei | h0sint.com | template: [robots-txt], name: [robots.txt file] |
| nuclei | h0sint.com | template: [rdap-whois], name: [RDAP WHOIS] Extracted Data: [Squarespace Domains LLC] |
| nuclei | h0sint.com | template: [rdap-whois], name: [RDAP WHOIS] Extracted Data: [2026-06-15T20:00:16Z] |
| nuclei | h0sint.com | template: [rdap-whois], name: [RDAP WHOIS] Extracted Data: [AADEN.NS.CLOUDFLARE.COM,JUNE.NS.CLOUDFLA |
| nuclei | h0sint.com | template: [rdap-whois], name: [RDAP WHOIS] Extracted Data: [client delete prohibited,client transfer |
| nuclei | h0sint.com | template: [rdap-whois], name: [RDAP WHOIS] Extracted Data: [abuse-complaints@squarespace.com] |
| nuclei | h0sint.com | template: [rdap-whois], name: [RDAP WHOIS] Extracted Data: [2029-06-15T20:00:16Z] |
| nuclei | h0sint.com | template: [rdap-whois], name: [RDAP WHOIS] Extracted Data: [3827] |
| nuclei | h0sint.com | template: [rdap-whois], name: [RDAP WHOIS] Extracted Data: [false] |
| nuclei | h0sint.com | template: [rdap-whois], name: [RDAP WHOIS] Extracted Data: [http://squarespace.domains] |
| nuclei | h0sint.com | template: [rdap-whois], name: [RDAP WHOIS] Extracted Data: [tel:1-646-693-5324] |
| nuclei | h0sint.com | template: [rdap-whois], name: [RDAP WHOIS] Extracted Data: [2026-07-10T21:03:19Z] |
| nuclei | h0sint.com | template: [txt-fingerprint], name: [DNS TXT Record Detected] Extracted Data: ["google-site-verificat |
| nuclei | h0sint.com | template: [spf-record-detect], name: [SPF Record - Detection] Extracted Data: [v=spf1 include:_spf.g |
| nuclei | h0sint.com | template: [caa-fingerprint], name: [CAA Record] |
| nuclei | h0sint.com | template: [mx-fingerprint], name: [MX Record Detection] Extracted Data: [5 alt2.aspmx.l.google.com., |
| nuclei | h0sint.com | template: [nameserver-fingerprint], name: [NS Record Detection] Extracted Data: [aaden.ns.cloudflare |
| nuclei | h0sint.com | template: [mx-service-detector], name: [Google Apps] |
| nuclei | h0sint.com | template: [aaaa-fingerprint], name: [AAAA Record - IPv6 Detection] Extracted Data: [2606:4700:3033:: |
| nuclei | h0sint.com | template: [aaaa-fingerprint], name: [AAAA Record - IPv6 Detection] Extracted Data: [2606:4700:3034:: |
| nuclei | h0sint.com | template: [mx-fingerprint], name: [MX Record Detection] Extracted Data: [10 alt4.aspmx.l.google.com. |
| nuclei | h0sint.com | template: [tls-version], name: [TLS Version - Detect] Extracted Data: [tls13] |
| nuclei | h0sint.com | template: [tls-version], name: [TLS Version - Detect] Extracted Data: [tls12] |
| nuclei | h0sint.com | template: [addeventlistener-detect], name: [Add DOM EventListener - Detection] |
| nuclei | h0sint.com | template: [nginx-config], name: [Nginx Config - Detect] |
| nuclei | h0sint.com | template: [robots-txt-endpoint], name: [robots.txt endpoint prober] |
| nuclei | h0sint.com | template: [tls-version], name: [TLS Version - Detect] Extracted Data: [tls12] |
| nuclei | h0sint.com | template: [tls-version], name: [TLS Version - Detect] Extracted Data: [tls13] |
| nuclei | h0sint.com | template: [exposed-gitignore], name: [Gitignore Config - Detect] |
| nuclei | h0sint.com | template: [package-json], name: [NPM package.json Disclosure] |
| nuclei | h0sint.com | template: [robots-txt], name: [robots.txt file] |
| nuclei | h0sint.com | template: [readme-md], name: [README.md file disclosure] |
| nuclei | h0sint.com | template: [rdap-whois], name: [RDAP WHOIS] Extracted Data: [client transfer prohibited,client delete |
| nuclei | h0sint.com | template: [mx-fingerprint], name: [MX Record Detection] Extracted Data: [1 aspmx.l.google.com.,10 al |
| nuclei | h0sint.com | template: [spf-record-detect], name: [SPF Record - Detection] Extracted Data: [v=spf1 include:_spf.g |
| nuclei | h0sint.com | template: [ssl-issuer], name: [Detect SSL Certificate Issuer] Extracted Data: [Google Trust Services |
| nuclei | h0sint.com | template: [caa-fingerprint], name: [CAA Record] |
| nuclei | h0sint.com | template: [ssl-dns-names], name: [SSL DNS Names] Extracted Data: [h0sint.com] |
| nuclei | h0sint.com | template: [txt-fingerprint], name: [DNS TXT Record Detected] Extracted Data: ["google-site-verificat |
| nuclei | h0sint.com | template: [nameserver-fingerprint], name: [NS Record Detection] Extracted Data: [aaden.ns.cloudflare |
| nuclei | h0sint.com | template: [mx-service-detector], name: [Google Apps] |
| nuclei | h0sint.com | template: [aaaa-fingerprint], name: [AAAA Record - IPv6 Detection] Extracted Data: [2606:4700:3034:: |
| nuclei | h0sint.com | template: [missing-sri], name: [Missing Subresource Integrity] Extracted Data: [https://fonts.google |
| nuclei | h0sint.com | template: [readme-md], name: [README.md file disclosure] |
| nuclei | h0sint.com | template: [readme-md], name: [README.md file disclosure] |
| nuclei | h0sint.com | template: [addeventlistener-detect], name: [Add DOM EventListener - Detection] |
| nuclei | h0sint.com | template: [email-extractor], name: [Email Extractor] Extracted Data: [knowone@h0sint.com] |
| nuclei | h0sint.com | template: [addeventlistener-detect], name: [Add DOM EventListener - Detection] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [content-security-policy] |
| nuclei | h0sint.com | template: [robots-txt], name: [robots.txt file] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [x-permitted-cross-domain-policies] |
| nuclei | h0sint.com | template: [robots-txt], name: [robots.txt file] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [cross-origin-embedder-policy] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [x-frame-options] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [cross-origin-opener-policy] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [strict-transport-security] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [cross-origin-resource-policy] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [cross-origin-resource-policy] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [x-permitted-cross-domain-policies] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [permissions-policy] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [permissions-policy] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [x-frame-options] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [content-security-policy] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [cross-origin-opener-policy] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [cross-origin-embedder-policy] |
| nuclei | h0sint.com | template: [http-missing-security-headers], name: [strict-transport-security] |
| nuclei | h0sint.com | template: [robots-txt-endpoint], name: [robots.txt endpoint prober] |
| nuclei | h0sint.com | template: [robots-txt-endpoint], name: [robots.txt endpoint prober] |
| nuclei | h0sint.com | template: [aaaa-fingerprint], name: [AAAA Record - IPv6 Detection] Extracted Data: [2606:4700:3033:: |
| nuclei | h0sint.com | template: [aaaa-fingerprint], name: [AAAA Record - IPv6 Detection] Extracted Data: [2606:4700:3034:: |
| nuclei | h0sint.com | template: [caa-fingerprint], name: [CAA Record] |
| nuclei | h0sint.com | template: [ssl-issuer], name: [Detect SSL Certificate Issuer] Extracted Data: [Google Trust Services |
| nuclei | h0sint.com | template: [ssl-dns-names], name: [SSL DNS Names] Extracted Data: [h0sint.com] |
| nuclei | h0sint.com | template: [spf-record-detect], name: [SPF Record - Detection] Extracted Data: [v=spf1 include:_spf.g |
| nuclei | h0sint.com | template: [mx-service-detector], name: [Google Apps] |
| nuclei | h0sint.com | template: [mx-fingerprint], name: [MX Record Detection] Extracted Data: [5 alt1.aspmx.l.google.com., |
| nuclei | h0sint.com | template: [nameserver-fingerprint], name: [NS Record Detection] Extracted Data: [aaden.ns.cloudflare |
| nuclei | h0sint.com | template: [mx-fingerprint], name: [MX Record Detection] Extracted Data: [5 alt2.aspmx.l.google.com., |
| nuclei | h0sint.com | template: [txt-fingerprint], name: [DNS TXT Record Detected] Extracted Data: ["google-site-verificat |
| nuclei | h0sint.com | template: [ssl-dns-names], name: [SSL DNS Names] Extracted Data: [tease.h0sint.com] |
| nuclei | h0sint.com | template: [mx-fingerprint], name: [MX Record Detection] Extracted Data: [10 alt3.aspmx.l.google.com. |
| nuclei | tease.h0sint.com | template: [tls-version], name: [TLS Version - Detect] Extracted Data: [tls13] |
| nuclei | tease.h0sint.com | template: [tls-version], name: [TLS Version - Detect] Extracted Data: [tls12] |
| nuclei | h0sint.com | template: [rdap-whois], name: [RDAP WHOIS] Extracted Data: [JUNE.NS.CLOUDFLARE.COM,AADEN.NS.CLOUDFLA |
| nuclei | tease.h0sint.com | template: [ssl-issuer], name: [Detect SSL Certificate Issuer] Extracted Data: [Google Trust Services |
| nuclei | tease.h0sint.com | template: [ssl-dns-names], name: [SSL DNS Names] Extracted Data: [tease.h0sint.com] |
| nuclei | h0sint.com | template: [mx-fingerprint], name: [MX Record Detection] Extracted Data: [1 aspmx.l.google.com.,10 al |
| nuclei | h0sint.com | template: [security-txt], name: [security.txt File] Extracted Data: [ mailto:security@h0sint.com] |
| nuclei | h0sint.com | template: [aaaa-fingerprint], name: [AAAA Record - IPv6 Detection] Extracted Data: [2606:4700:3033:: |
| nuclei | h0sint.com | template: [mx-fingerprint], name: [MX Record Detection] Extracted Data: [5 alt1.aspmx.l.google.com., |
| nuclei | h0sint.com | template: [nameserver-fingerprint], name: [NS Record Detection] Extracted Data: [june.ns.cloudflare. |

---

## Infrastructure

### DNS Records

- `h0sint.com` (in-scope)
- `tease.h0sint.com` (in-scope)
- `aaden.ns.cloudflare.com` (affiliate)
- `aspmx.l.google.com` (affiliate)
- `alt4.aspmx.l.google.com` (affiliate)
- `alt2.aspmx.l.google.com` (affiliate)
- `alt1.aspmx.l.google.com` (affiliate)
- `alt3.aspmx.l.google.com` (affiliate)
- `june.ns.cloudflare.com` (affiliate)
- `login.windows.net` (affiliate)
- `try.h0sint.com` (in-scope)

### IP Addresses


### Open Ports

| Host | Port | Banner |
|------|------|--------|
| h0sint.com | 80 |  |
| h0sint.com | 443 |  |
| tease.h0sint.com | 80 |  |
| tease.h0sint.com | 443 |  |
| try.h0sint.com | 80 |  |
| try.h0sint.com | 443 |  |

---

## Technologies

| Name | Version | Host |
|------|---------|------|
| cpe:/a:cloudflare:cloudflare | - | h0sint.com |
| cpe:/a:cloudflare:cloudflare | - | tease.h0sint.com |
| cpe:/a:cloudflare:cloudflare | - | tease.h0sint.com |
| cloudflare | - | tease.h0sint.com |
| cloudflare | - | tease.h0sint.com |
| google font api | - | tease.h0sint.com |
| google-font-api | - | tease.h0sint.com |
| cpe:/a:cloudflare:cloudflare | - | h0sint.com |
| cloudflare | - | h0sint.com |
| cloudflare | - | h0sint.com |
| google-font-api | - | h0sint.com |

---

## Emails

- `security@h0sint.com` (via h0sint.com)
- `knowone@h0sint.com`
- `contact@h0sint.com`

---

## Recommendations

### Immediate (P1)

- Implement Subresource Integrity (SRI) hashes on all third-party script/stylesheet references — addresses the only `undiscountable` Low finding.
- Add rate limiting + CAPTCHA/honeypot to newsletter submission form — mitigates email-bombing abuse (Info finding with real-world nuisance impact).

### Short term (P2)

- Block public access to `.github/workflows/` and `Dockerfile*` via Cloudflare Page Rules or origin config — removes Low hygiene findings.
- Deploy `Cross-Origin-Resource-Policy: same-origin` header via Cloudflare Workers — closes Info header gap.
- Verify DMARC/SPF/DKIM alignment for `h0sint.com` — reduces phishing surface from enumerated emails.

### Medium term (P3)

- Establish vulnerability scanning cadence (monthly external, quarterly authenticated) — satisfies IG2 "vulnerability scanning" expected control.
- Implement centralized logging/SIEM (control not verified by external scan — confirm via evidence) (even lightweight: Cloudflare Logpush to Splunk/ELK/Graylog) — satisfies IG2 "SIEM/logging" control.
- Draft and tabletop-test an incident response plan — satisfies IG2 "incident response plan" control.
