CodeForPhilly / CodeForPhilly/laddr

Hardening Improvements - security header recommendations

Offen
#223 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Smarty
Sterne
62
Forks
34
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

Some recommendations from Sucuri:

- Missing security header for ClickJacking Protection. Alternatively, you can use Content-Security-Policy: frame-ancestors 'none'.
- https://docs.sucuri.net/warnings/hardening/security-headers-x-frame-options/
- You can enable it by modifying your Apache settings or your `.htaccess` file - on server side
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors

- Missing security header to prevent Content Type sniffing.
- https://docs.sucuri.net/warnings/hardening/security-headers-x-content-type-nosniff/
- You can enable it by modifying your Apache settings or your `.htaccess` file - on server side

- Missing Strict-Transport-Security security header
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
- applicable only to HTTPS sites on Laddr, can it be configurable per Emergence instance/site?
- should be done on server side

- Missing Content-Security-Policy directive.
- https://blog.sucuri.net/2018/04/content-security-policy.html
- We recommend to add the following CSP directives (you can use default-src if all values are the same): script-src, object-src, base-uri, frame-src
- try to block executing scripts added in content (i.e. page, buzz, project description, comment etc)
- Use "report-uri" to log failed requests. Endpoint to send report json to: https://report-uri.com/#prices (free up to 10.000 requests per month); when testing in production use "report-only" to send reports to URL endpoint what would be blocked by set CSP rules.

- Leaked PHP version. Your site is displaying your PHP version in the HTTP headers. Please set expose_php = Off.
- https://secure.php.net/manual/en/ini.core.php
- this should be done on server side (Emergence hosting)

Check full report at:
https://sitecheck.sucuri.net/results/codeforphilly.org (same results are for other Laddr instances)

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Rechercherichtung

Start by reviewing the Apache settings or .htaccess configuration mentioned in the issue and determine which security headers are controlled by Emergence hosting versus the Laddr instance. Check how HTTPS sites are configured and whether PHP exposes its version. Done means the applicable headers and PHP setting are enabled without breaking existing sites.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
apache, php
Bereich
infrastructure, security
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.