Re: New NSE Script http-security-headers.nse

Robin Wood <[email protected]>
Newsgroups gmane.comp.security.nmap.devel
Message-ID <CALmccy4J_mxsmxtON7BNk0J+-wn-i66gVv4LpCfBqunvunozFA@mail.gmail.com>
Why not check the new referrer header as well?

https://scotthelme.co.uk/a-new-security-header-referrer-policy/

Robin

On Wed, 31 May 2017, 12:19 Vinamra Bhatia, <[email protected]> wrote:

> Hello All,
>
> This is regarding a NSE Script my mentor and I were working last week.
>
> The script checks for the HTTP response headers related to security given
> in OWASP Secure Headers Project, shows whether they are configured and
> gives a brief description of them.
>
> The script requests the server for the header with http.head and parses it
> to list headers found with their configurations. It checks for HSTS(HTTP
> Strict Transport Security), HPKP(HTTP Public Key Pins), X-Frame-Options,
> X-XSS-Protection, X-Content-Type-Options, Content-Security-Policy and
> X-Permitted-Cross-Domain-Policies.
>
> There is another script titled http-hsts-verify. The new script already
> includes the checks provided by http-hsts-verify and does much more
> comprehensive testing. Hence when we commit the new script, we should
> remove the other one.
>
> Github PR for the same https://github.com/nmap/nmap/pull/793
>
> We would love to take suggestions on this. Thanks and have a  great day!
>
> With Regards
> Vinamra
>
>
> _______________________________________________
> Sent through the dev mailing list
> https://nmap.org/mailman/listinfo/dev
> Archived at http://seclists.org/nmap-dev/

_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.