2021-07-28 12:40:20 +00:00
|
|
|
id: http-missing-security-headers
|
|
|
|
|
|
|
|
info:
|
|
|
|
name: HTTP Missing Security Headers
|
2022-05-17 20:49:08 +00:00
|
|
|
author: socketz,geeknik,G4L1T0,convisoappsec,kurohost,dawid-czarnecki,forgedhallpass
|
2021-07-28 12:40:20 +00:00
|
|
|
severity: info
|
2022-05-20 21:38:52 +00:00
|
|
|
description: |
|
|
|
|
This template searches for missing HTTP security headers. The impact of these missing headers can vary.
|
2021-09-03 17:05:58 +00:00
|
|
|
tags: misconfig,generic
|
2021-07-28 12:40:20 +00:00
|
|
|
|
|
|
|
requests:
|
|
|
|
- method: GET
|
|
|
|
path:
|
|
|
|
- "{{BaseURL}}"
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2021-07-28 12:40:20 +00:00
|
|
|
redirects: true
|
|
|
|
max-redirects: 3
|
|
|
|
matchers-condition: or
|
|
|
|
matchers:
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: strict-transport-security
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)strict-transport-security', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: content-security-policy
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)content-security-policy', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-12-29 14:36:58 +00:00
|
|
|
name: permission-policy
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)permission-policy', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-12-29 14:36:58 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: x-frame-options
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)x-frame-options', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: x-content-type-options
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)x-content-type-options', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: x-permitted-cross-domain-policies
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)x-permitted-cross-domain-policies', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: referrer-policy
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)referrer-policy', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: clear-site-data
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)clear-site-data', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: cross-origin-embedder-policy
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)cross-origin-embedder-policy', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: cross-origin-opener-policy
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)cross-origin-opener-policy', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: cross-origin-resource-policy
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)cross-origin-resource-policy', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: access-control-allow-origin
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)access-control-allow-origin', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: access-control-allow-credentials
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)access-control-allow-credentials', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: access-control-expose-headers
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)access-control-expose-headers', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: access-control-max-age
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)access-control-max-age', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: access-control-allow-methods
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)access-control-allow-methods', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|
2021-09-03 16:54:11 +00:00
|
|
|
|
2022-05-17 20:49:08 +00:00
|
|
|
- type: dsl
|
2021-09-03 16:54:11 +00:00
|
|
|
name: access-control-allow-headers
|
2022-05-17 20:49:08 +00:00
|
|
|
dsl:
|
|
|
|
- "!regex('(?i)access-control-allow-headers', all_headers)"
|
|
|
|
- "status_code != 301 && status_code != 302"
|
|
|
|
condition: and
|