Flipkart icon Flipkart HackerOne

www.cleartrip.com


Endpoints (4 of 4)

Page 1 of 1

Path
Port
Status Code
Content-Length
Title
Resp Headers
/
443
200
66829
Cleartrip: #1 Site for Booking Flights Tickets & Hotels Online - Get Best Travel Deals

Content-Type: text/html

/
80
301
174
301 Moved Permanently

Location: https://www.cleartrip.com/

Content-Type: text/html

/c3650cdf-216a-4ba2-80b0-9d6c540b105e58d2670b-ea0f-484e-b88c-0e2c1499ec9bd71e4b42-8570-44e3-89b6-845326fa43b6
443
200
78539
None

Content-Type: text/javascript

/raven-web-sdk/static/js/main.min.js
443
200
262769
None

Content-Type: application/javascript

  • Path: /
  • Port: 443
  • Status Code: 200
  • Title: Cleartrip: #1 Site for Booking Flights Tickets & Hotels Online - Get Best Travel Deals
  • Age: 68107

    Via: 1.1 8fcaa17120d24b3b8568c63a2805148e.cloudfront.net (CloudFront), 1.1 google

    Date: Mon, 06 May 2024 14:31:06 GMT

    Vary: Accept-Encoding, rbz-no-cache

    Server: rhino-core-shield

    Alt-Svc: clear

    X-Cache: Hit from cloudfront

    X-Amz-Cf-Id: M1X2ZYS2Eac8d4nOF5sAGy2tSp-uDVuePIiHSiECSdzTseN3KEI8fg==

    Content-Type: text/html

    X-Amz-Cf-Pop: BOM78-P9

    Cache-Control: no-store, no-cache, must-revalidate, max-age=0

    X-Frame-Options: SAMEORIGIN

    Originalhostheader: www.cleartrip.com

    X-Content-Type-Options: nosniff

    Strict-Transport-Security: max-age=31536000; includeSubDomains

    X-Amz-Server-Side-Encryption: AES256

    Content-Security-Policy-Report-Only: script-src 'unsafe-eval' 'unsafe-inline' 'self' storage.googleapis.com cdn.ravenjs.com tpc.googlesyndication.com maps.googleapis.com cdn.ampproject.org sb.scorecardresearch.com cdnjs.cloudflare.com www.google.com cdn.jsdelivr.net *.google-analytics.com clk.2trk.info client.px-cloud.net polyfill.io d2r1yp2w7bby2u.cloudfront.net www.googletagmanager.com www.googleoptimize.com wzrkt.com js-agent.newrelic.com googleads.g.doubleclick.net bat.bing.com *.hotjar.com www.googleadservices.com s.adx.io *.criteo.com migs.mastercard.com.au connect.facebook.net cdn.branch.io static.ads-twitter.com www.recaptcha.net app.link www.gstatic.com browser.sentry-cdn.com *.cltpstatic.com cdn.inspectlet.com static.criteo.net *.nr-data.net cdn.preciso.net eu1.clevertap-prod.com events.statsigapi.net; style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com storage.googleapis.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net use.fontawesome.com *.cltpstatic.com rsms.me fonts.googleapis.com fontlibrary.org blob:; connect-src 'self' google.com *.google.com *.doubleclick.net sentry.io sdk.joinsherpa.io cdn.preciso.net cdn.ampproject.org *.creativecdn.com events.statsigapi.net eu1.clevertap-prod.com featuregates.org *.facebook.com *.criteo.com cdn.ravenjs.com *.google-analytics.com *.branch.io *.px-cloud.net *.cltpstatic.com *.nr-data.net www.google.co.in bat.bing.com vc.hotjar.io in.hotjar.com b.px-cdn.net *.cleartrip.com hn.inspectlet.com *.salesforce.com; frame-src 'self' tpc.googlesyndication.com *.creativecdn.com *.doubleclick.net vars.hotjar.com *.criteo.com static.criteo.net ck.2trk.info my.rtmarks.net redirtrack.tech www.recaptcha.net; form-action api.razorpay.com; font-src 'self' use.fontawesome.com cdnjs.cloudflare.com maxcdn.bootstrapcdn.com storage.googleapis.com rsms.me *.cltpstatic.com fonts.gstatic.com fontlibrary.org; img-src data: https://*; manifest-src 'self' fastui.cltpstatic.com; media-src 'self' fastui.cltpstatic.com; object-src 'none'; base-uri 'self'; worker-src 'self'; frame-ancestors 'self'; report-uri https://csp-flkt.domdog.io/report-uri/flipkart.com/2/1-2;

  • First snapshot: 11 months, 3 weeks ago
  • Latest snapshot: 11 months, 3 weeks ago
  • Path: /
  • Port: 80
  • Status Code: 301
  • Title: 301 Moved Permanently
  • Via: 1.1 google

    Date: Mon, 06 May 2024 14:31:06 GMT

    Vary: rbz-no-cache

    Server: rhino-core-shield

    Location: https://www.cleartrip.com/

    Content-Type: text/html

    Cache-Control: no-store, no-cache, must-revalidate, max-age=0

    Content-Length: 174

    X-Frame-Options: SAMEORIGIN

    Strict-Transport-Security: max-age=31536000; includeSubDomains

    Content-Security-Policy-Report-Only: script-src 'unsafe-eval' 'unsafe-inline' 'self' storage.googleapis.com cdn.ravenjs.com tpc.googlesyndication.com maps.googleapis.com cdn.ampproject.org sb.scorecardresearch.com cdnjs.cloudflare.com www.google.com cdn.jsdelivr.net *.google-analytics.com clk.2trk.info client.px-cloud.net polyfill.io d2r1yp2w7bby2u.cloudfront.net www.googletagmanager.com www.googleoptimize.com wzrkt.com js-agent.newrelic.com googleads.g.doubleclick.net bat.bing.com *.hotjar.com www.googleadservices.com s.adx.io *.criteo.com migs.mastercard.com.au connect.facebook.net cdn.branch.io static.ads-twitter.com www.recaptcha.net app.link www.gstatic.com browser.sentry-cdn.com *.cltpstatic.com cdn.inspectlet.com static.criteo.net *.nr-data.net cdn.preciso.net eu1.clevertap-prod.com events.statsigapi.net; style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com storage.googleapis.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net use.fontawesome.com *.cltpstatic.com rsms.me fonts.googleapis.com fontlibrary.org blob:; connect-src 'self' google.com *.google.com *.doubleclick.net sentry.io sdk.joinsherpa.io cdn.preciso.net cdn.ampproject.org *.creativecdn.com events.statsigapi.net eu1.clevertap-prod.com featuregates.org *.facebook.com *.criteo.com cdn.ravenjs.com *.google-analytics.com *.branch.io *.px-cloud.net *.cltpstatic.com *.nr-data.net www.google.co.in bat.bing.com vc.hotjar.io in.hotjar.com b.px-cdn.net *.cleartrip.com hn.inspectlet.com *.salesforce.com; frame-src 'self' tpc.googlesyndication.com *.creativecdn.com *.doubleclick.net vars.hotjar.com *.criteo.com static.criteo.net ck.2trk.info my.rtmarks.net redirtrack.tech www.recaptcha.net; form-action api.razorpay.com; font-src 'self' use.fontawesome.com cdnjs.cloudflare.com maxcdn.bootstrapcdn.com storage.googleapis.com rsms.me *.cltpstatic.com fonts.gstatic.com fontlibrary.org; img-src data: https://*; manifest-src 'self' fastui.cltpstatic.com; media-src 'self' fastui.cltpstatic.com; object-src 'none'; base-uri 'self'; worker-src 'self'; frame-ancestors 'self'; report-uri https://csp-flkt.domdog.io/report-uri/flipkart.com/2/1-2;

  • First snapshot: 11 months, 3 weeks ago
  • Latest snapshot: 11 months, 3 weeks ago
  • Path: /c3650cdf-216a-4ba2-80b0-9d6c540b105e58d2670b-ea0f-484e-b88c-0e2c1499ec9bd71e4b42-8570-44e3-89b6-845326fa43b6
  • Port: 443
  • Status Code: 200
  • Title: None
  • Content-Type: text/javascript
  • Content-Length: 78539
  • First snapshot: 11 months, 3 weeks ago
  • Latest snapshot: 11 months, 3 weeks ago
  • Path: /raven-web-sdk/static/js/main.min.js
  • Port: 443
  • Status Code: 200
  • Title: None
  • Content-Type: application/javascript
  • Content-Length: 262769
  • First snapshot: 11 months, 3 weeks ago
  • Latest snapshot: 11 months, 3 weeks ago

Page 1 of 1