Risk Grade: C
Acme Corp's external security posture reveals moderate-to-significant exposure across multiple attack vectors. The RECON scan identified 18 findings, including 2 HIGH severity issues requiring immediate attention: an expired SSL certificate on the shop subdomain and an open MySQL port exposed in Shodan intelligence. Additionally, critical security headers are missing, outdated technologies are running, and email security remains incomplete. While foundational controls exist, multiple configuration gaps and technology debt create material risk.
| Subdomain | Status | Technology | Notes |
|---|---|---|---|
| acme-corp.com | ✓ Active | React/Nginx | Main domain, Cloudflare CDN |
| www.acme-corp.com | ✓ Active | React/Nginx | Primary web application |
| api.acme-corp.com | ✓ Active | Node.js | REST API endpoint |
| shop.acme-corp.com | ⚠ Active (cert expired) | WooCommerce/Apache | E-commerce platform |
| mail.acme-corp.com | ✓ Active | Postfix | Mail server |
| staging.acme-corp.com | ✓ Active | Apache/MySQL | Development environment |
SSL Certificate Status
Main domain certificate is valid (expires Sept 2026), but shop.acme-corp.com certificate expired on Feb 28, 2026. This creates browser warnings and blocks e-commerce transactions.
DNS Resolution
All nameservers resolve correctly. Zone transfers blocked (good). DNSSEC not enabled (optional).
Email Authentication
SPF configured but too permissive. DMARC missing. DKIM partially implemented (only for primary domain). Increases phishing risk.
CDN & Global Delivery
Cloudflare CDN active on main domain, providing DDoS protection and caching. Good for performance and availability.
Domain Expiration
Domain expires May 20, 2026 (44 days). Critical action required to renew immediately.
Fingerprinting and Shodan reconnaissance identified 12+ technologies running across Acme Corp's infrastructure:
Notable Issues:
The RECON scan identified 18 findings across infrastructure, security headers, and technology debt. The highest-severity issues are listed first.
| Phase | Duration | Effort | Resources |
|---|---|---|---|
| Priority 1 | 3-5 days | 4-6 hours | DevOps + Infrastructure |
| Priority 2 | 20-30 days | 20-30 hours | DevOps + Development |
| Priority 3 | 60-90 days | 30-40 hours | Full engineering team |
The RECON assessment covers reconnaissance, technology identification, and configuration analysis. To identify active vulnerabilities, exploit paths, and compliance gaps, consider upgrading to a FULL Scan, which includes:
The FULL scan will identify active vulnerabilities (e.g., unpatched CVEs, exposed endpoints, weak authentication) and provide comprehensive compliance reporting essential for audits and stakeholder communication.