Content-Security-Policy: default-src * data:; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://*.facebook.com http://*.facebook.com https://*.facebook.net http://*.facebook.net https://*.fbcdn.net http://*.fbcdn.net http://*.twitter.com https://*.twitter.com http://*.google.com http://*.googleapis.com https://*.googleapis.com http://*.gstatic.com https://*.gstatic.com https://*.google.com http://*.google-analytics.com https://*.google-analytics.com https://*.doubleclick.net http://*.doubleclick.net https://*.googleadservices.com http://*.googleadservices.com http://*.schema.org https://*.schema.org http://*.w3.org https://*.w3.org http://*.googletagmanager.com https://*.googletagmanager.com http://*.ampproject.org https://*.ampproject.org; style-src 'unsafe-inline' *
Access-Control-Allow-Origin: *
X-UA-Compatible: IE=edge
Cache-control: must-revalidate
Timing-Allow-Origin: *
Strict-Transport-Security: max-age=31536000; includeSubDomains
P3P: policyref="/w3c/p3p.xml", CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Expires: Wed, 07 Mar 2018 14:59:14 GMT
Set-Cookie: PHPSESSID=8ganpek2mlkts275he21qd67b4; path=/
HTTP/1.1 200 OK
Last-Modified: Wed, 28 Feb 2018 13:59:14 GMT
X-Content-Type-Options: nosniff
Content-Security-Policy: default-src * data:; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://*.facebook.com http://*.facebook.com https://*.facebook.net http://*.facebook.net https://*.fbcdn.net http://*.fbcdn.net http://*.twitter.com https://*.twitter.com http://*.google.com http://*.googleapis.com https://*.googleapis.com http://*.gstatic.com https://*.gstatic.com https://*.google.com http://*.google-analytics.com https://*.google-analytics.com https://*.doubleclick.net http://*.doubleclick.net https://*.googleadservices.com http://*.googleadservices.com http://*.schema.org https://*.schema.org http://*.googletagmanager.com https://*.googletagmanager.com http://*.ampproject.org https://*.ampproject.org; style-src 'unsafe-inline' *
Transfer-Encoding: chunked
X-XSS-Protection: 1; mode=block
Cache-Control: no-transform
Date: Wed, 28 Feb 2018 14:59:14 GMT
X-Powered-By: PHP/5.4.45
Connection: keep-alive
Server: Apache
Vary: Accept-Encoding,User-Agent
X-XSS-Protection: 1; mode=block
Content-Type: text/html; charset=UTF-8
Pragma: no-cache