LEARN · SECURITY-HEADERS
Security headers
The basic HTTP security headers: nosniff, Referrer-Policy, Permissions-Policy and hiding the server version.
WHAT IT IS
They are instructions your server sends with each page so the browser applies protections: do not guess file types (nosniff), limit what is shared when leaving (Referrer-Policy) or which features the site may use (Permissions-Policy).
WHY IT MATTERS
They are cheap to add and close known doors. Their absence is not a vulnerability by itself, but it is a sign of careless configuration. Showing the server version eases reconnaissance for anyone looking for flaws.
COMMON MISTAKES
- Adding them in application code and forgetting error pages or static files (better at the web server).
- Referrer-Policy: unsafe-url.
- Leaving server_tokens on in nginx or X-Powered-By in the application.
EXAMPLE
X-Content-Type-Options: nosniff Referrer-Policy: strict-origin-when-cross-origin Permissions-Policy: camera=(), microphone=(), geolocation=() # nginx: server_tokens off;
HOW WE CHECK IT
- HDR_XCTO v1.0.0 — That `X-Content-Type-Options: nosniff` is sent.
- HDR_REFERRER_POLICY v1.0.0 — That the site defines what referrer information is shared when navigating to other sites.
- HDR_PERMISSIONS_POLICY v1.0.0 — That browser features (camera, microphone, geolocation…) the site may use are restricted.
- HDR_VERSION_DISCLOSURE v1.0.0 — Whether the `Server` or `X-Powered-By` headers reveal software and version.