Access-Control-Allow-Origin: *
Transfer-Encoding: chunked
X-Frame-Options: DENY
Last-Modified: Wed, 07 Feb 2018 06:41:10 GMT
Strict-Transport-Security: max-age=31536000; includeSubDomains
Vary: Accept-Encoding,User-Agent
X-XSS-Protection: 1; mode=block
Server: nginx
Expires: Wed, 14 Feb 2018 07:41:10 GMT
Set-Cookie: PHPSESSID=87f602db755269c00054fc9e8a4c9091; path=/
Content-Security-Policy: default-src * data:; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://*.facebook.com http://*.facebook.com https://*.facebook.net http://*.facebook.net https://*.fbcdn.net http://*.fbcdn.net http://*.twitter.com https://*.twitter.com http://*.google.com http://*.google.hu http://*.googleapis.com https://*.googleapis.com http://*.gstatic.com https://*.gstatic.com https://*.google.com https://*.google.hu http://*.google-analytics.com https://*.google-analytics.com https://*.doubleclick.net http://*.doubleclick.net https://*.googleadservices.com http://*.googleadservices.com http://*.schema.org https://*.schema.org http://*.googletagmanager.com https://*.googletagmanager.com http://*.ampproject.org https://*.ampproject.org; style-src 'unsafe-inline' *
Content-Type: text/html; charset=UTF-8
X-UA-Compatible: IE=edge
X-Frame-Options: deny
Pragma: no-cache
Timing-Allow-Origin: *
Date: Wed, 07 Feb 2018 07:41:10 GMT
X-XSS-Protection: 1; mode=block
Content-Security-Policy: default-src * data:; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://*.facebook.com http://*.facebook.com https://*.facebook.net http://*.facebook.net https://*.fbcdn.net http://*.fbcdn.net http://*.twitter.com https://*.twitter.com http://*.google.com http://*.google.hu http://*.googleapis.com https://*.googleapis.com http://*.gstatic.com https://*.gstatic.com https://*.google.com https://*.google.hu http://*.google-analytics.com https://*.google-analytics.com https://*.doubleclick.net http://*.doubleclick.net https://*.googleadservices.com http://*.googleadservices.com http://*.schema.org https://*.schema.org http://*.w3.org https://*.w3.org http://*.googletagmanager.com https://*.googletagmanager.com http://*.ampproject.org https://*.ampproject.org; style-src 'unsafe-inline' *
HTTP/1.1 200 OK
Cache-control: must-revalidate
X-Content-Type-Options: nosniff
Connection: keep-alive
P3P: policyref="/w3c/p3p.xml", CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Cache-Control: no-transform