HTTP/1.1 302 Found
Server: nginx/1.20.1
Date: Thu, 28 Oct 2021 03:07:23 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Set-Cookie: PHPSESSID=ld38qdfcl8qijvo3jc3t3uotbp; expires=Fri, 29-Oct-2021 03:07:23 GMT; Max-Age=86400; path=/; domain=stock.de; HttpOnly; SameSite=Lax
Location: https://stock.de/
Content-Security-Policy-Report-Only: font-src https://fonts.googleapis.com https://fonts.gstatic.com fonts.googleapis.com data: *.cloudfront.net *.fontawesome.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com player.vimeo.com www.googletagmanager.com https://www.youtube.com https://www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com https://maps.gstatic.com https://maps.googleapis.com https://developers.google.com https://i.ytimg.com piwik.guehring.de *.google.com *.google.de *.amazonaws.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.googletagmanager.com www.youtube.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://www.googleapis.com/ https://www.google-analytics.com/ https://www.googletagmanager.com piwik.guehring.de *.amazonaws.com *.cloudfront.net *.userlike.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com https://fonts.googleapis.com https://www.gstatic.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net https://www.google-analytics.com/ *.doubleclick.net *.amazonaws.com *.userlike.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: Allow From : service.ariba.com
Vary: Accept-Encoding
Pragma: no-cache
Expires: -1
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
HTTP/2 200
server: nginx/1.20.1
date: Thu, 28 Oct 2021 03:07:24 GMT
content-type: text/html; charset=UTF-8
content-security-policy-report-only: font-src https://fonts.googleapis.com https://fonts.gstatic.com fonts.googleapis.com data: *.cloudfront.net *.fontawesome.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com player.vimeo.com www.googletagmanager.com https://www.youtube.com https://www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com https://maps.gstatic.com https://maps.googleapis.com https://developers.google.com https://i.ytimg.com piwik.guehring.de *.google.com *.google.de *.amazonaws.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.googletagmanager.com www.youtube.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://www.googleapis.com/ https://www.google-analytics.com/ https://www.googletagmanager.com piwik.guehring.de *.amazonaws.com *.cloudfront.net *.userlike.com *.avada.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com https://fonts.googleapis.com https://www.gstatic.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net https://www.google-analytics.com/ *.doubleclick.net *.amazonaws.com *.userlike.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-frame-options: Allow From : service.ariba.com
vary: Accept-Encoding
pragma: no-cache
expires: -1
cache-control: no-store, no-cache, must-revalidate, max-age=0
accept-ranges: bytes
|