Security Lab · System Information
The kind of un-rewritable, decade-old stack that runs real back-office banking. Nemesis defends it in front, without touching the code.
| Application | OmniTrust Retail Portal v2.1.4 (2013 build) |
|---|---|
| Web framework | Next.js 15.5.x · a full major behind current (16.x); version scanners flag it as outdated |
| Web server | Apache/2.2.15 (CentOS) · EOL 2017, 40+ CVEs |
| Runtime | PHP 5.4.45 · EOL 2015 |
| App framework | ASP.NET 4.0.30319 (legacy modules) |
| Front-end | jQuery 1.7.2 (2012), Bootstrap 2.3.2 |
| Crypto | OpenSSL 1.0.1e · Heartbleed / POODLE era |
| Database | MySQL 5.5, direct string-concatenated queries |
Live HTTP response headers
| Server | — |
|---|---|
| X-Powered-By | — |
| X-AspNet-Version | — |
| X-Runtime-Stack | — |
| Content-Security-Policy | — |
| Strict-Transport-Security | — |
| X-Frame-Options | — |
Missing 5 security header(s): content-security-policy, strict-transport-security, x-frame-options, x-content-type-options, referrer-policy. This deployment is exposed to clickjacking, MIME sniffing and downgrade attacks.