NODE249 // TOOLSLAB/002 · EXPERIMENTES

LEARN · SECURITY-HEADERS

Security headers

The basic HTTP security headers: nosniff, Referrer-Policy, Permissions-Policy and hiding the server version.

WHAT IT IS

They are instructions your server sends with each page so the browser applies protections: do not guess file types (nosniff), limit what is shared when leaving (Referrer-Policy) or which features the site may use (Permissions-Policy).

WHY IT MATTERS

They are cheap to add and close known doors. Their absence is not a vulnerability by itself, but it is a sign of careless configuration. Showing the server version eases reconnaissance for anyone looking for flaws.

COMMON MISTAKES

EXAMPLE

X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()
# nginx: server_tokens off;

HOW WE CHECK IT