Date: Mon, 12 Jun 2017 15:13:46 GMT
X-Content-Type-Options: nosniff
HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
Keep-Alive: timeout=20
Server: nginx/1.8.0
Connection: keep-alive
X-Frame-Options: SAMEORIGIN
Content-Security-Policy: default-src 'self' https://cdn.zp.ru; img-src 'self' *.zp.ru *.zp.ru *.zarplata.ru *.zarplata.ru *.ngs.ru *.ngs.ru https://*.yandex.net https://api-maps.yandex.ru https://usage.trackjs.com https://www.google-analytics.com https://mc.yandex.ru https://counter.yadro.ru https://an.yandex.ru https://stats.g.doubleclick.net https://www.google.com https://www.google.ru data: https://i.giphy.com https://media.giphy.com https://www.tns-counter.ru; child-src 'self' *.zarplata.ru *.zarplata.ru https://webvisor.com https://www.googletagmanager.com; frame-src 'self' https://www.youtube.com https://reklama.ngs.ru https://api-maps.yandex.ru https://st.yandexadexchange.net https://yandexadexchange.net https://creativecdn.com; style-src https://cdn.zp.ru 'unsafe-inline'; object-src https://reklama.ngs.ru; script-src 'self' https://*.tns-counter.ru https://cdn.zp.ru 'unsafe-inline' 'unsafe-eval' https://www.google-analytics.com https://pagead2.googlesyndication.com https://www.googletagmanager.com https://mc.yandex.ru https://api-maps.yandex.ru https://reklama.ngs.ru https://yastatic.net https://an.yandex.ru; font-src https://cdn.zp.ru data:; connect-src https://www.zarplata.ru https://api.zp.ru https://stat.zp.ru https://passport.ngs.ru https://capture.trackjs.com https://mc.yandex.ru https://www.google-analytics.com https://job42.ru https://ngsrabota.com.ua https://ngsrabota.by https://ngsrabota.kz ws://kek.zp.ru; frame-ancestors 'self'; report-uri https://publiczpru.report-uri.io/r/default/csp/enforce; upgrade-insecure-requests
Transfer-Encoding: chunked
X-XSS-Protection: 1; mode=block
Vary: Accept-Encoding, User-Agent