CodeForPhilly / CodeForPhilly/laddr

Hardening Improvements - security header recommendations

オープン
#223 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Smarty
スター
62
フォーク
34
PR マージ指標
30日以内にマージされた PR はありません

説明

Some recommendations from Sucuri:

- Missing security header for ClickJacking Protection. Alternatively, you can use Content-Security-Policy: frame-ancestors 'none'.
- https://docs.sucuri.net/warnings/hardening/security-headers-x-frame-options/
- You can enable it by modifying your Apache settings or your `.htaccess` file - on server side
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors

- Missing security header to prevent Content Type sniffing.
- https://docs.sucuri.net/warnings/hardening/security-headers-x-content-type-nosniff/
- You can enable it by modifying your Apache settings or your `.htaccess` file - on server side

- Missing Strict-Transport-Security security header
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
- applicable only to HTTPS sites on Laddr, can it be configurable per Emergence instance/site?
- should be done on server side

- Missing Content-Security-Policy directive.
- https://blog.sucuri.net/2018/04/content-security-policy.html
- We recommend to add the following CSP directives (you can use default-src if all values are the same): script-src, object-src, base-uri, frame-src
- try to block executing scripts added in content (i.e. page, buzz, project description, comment etc)
- Use "report-uri" to log failed requests. Endpoint to send report json to: https://report-uri.com/#prices (free up to 10.000 requests per month); when testing in production use "report-only" to send reports to URL endpoint what would be blocked by set CSP rules.

- Leaked PHP version. Your site is displaying your PHP version in the HTTP headers. Please set expose_php = Off.
- https://secure.php.net/manual/en/ini.core.php
- this should be done on server side (Emergence hosting)

Check full report at:
https://sitecheck.sucuri.net/results/codeforphilly.org (same results are for other Laddr instances)

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

調査の方向性

まず、issue で言及されている Apache 設定または .htaccess 設定を確認し、どのセキュリティヘッダーが Emergence ホスティングによって制御され、どれが Laddr インスタンスによって制御されるのかを判断します。HTTPS サイトがどのように設定されているか、また PHP がそのバージョンを公開しているかを確認します。既存のサイトを壊すことなく、該当するヘッダーと PHP 設定が有効になっていれば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
apache, php
領域
infrastructure, security
issue の種類
機能追加
難易度
5/5
見積もり時間
1週間以上
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。