分類: 防禦

防禦

[資安]HTTP Strict Transport Security (HSTS) not implemented

HTTP Strict Transport Security (HSTS) not implemented 就 […]

Be the First to comment. Read More
防禦

[資安]Cookies without HttpOnly flag set

Cookies without HttpOnly flag set 請參考:HttpOnly – […]

Be the First to comment. Read More
防禦

[資安]TRACE method is enabled

HTTP TRACE method is enabled on this web server. In the […]

Be the First to comment. Read More
防禦

[資安]Clickjacking: X-Frame-Options header

其實 淺談IFrame式Clickjacking攻擊與防護 這篇文章就寫得很好了,他主要是來防禦別人把你的網站 […]

Be the First to comment. Read More
防禦

[資安]HSTS設定

你網站有https後這樣還不夠,大家還是希望要把http的連線都倒到https並且要在header上宣告才行 […]

Be the First to comment. Read More