Hardening Improvements - security header recommendations
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 25/100
- issue の種類
- 機能追加
- 明瞭さ
- 説明が足りない
- 活発さ
- 停滞
- 技術スタック
- apache, php
調査の方向性
まず、issue で言及されている Apache 設定または .htaccess 設定を確認し、どのセキュリティヘッダーが Emergence ホスティングによって制御され、どれが Laddr インスタンスによって制御されるのかを判断します。HTTPS サイトがどのように設定されているか、また PHP がそのバージョンを公開しているかを確認します。既存のサイトを壊すことなく、該当するヘッダーと PHP 設定が有効になっていれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Some recommendations from Sucuri:
-
Missing security header for ClickJacking Protection. Alternatively, you can use Content-Security-Policy: frame-ancestors 'none'.
- https://docs.sucuri.net/warnings/hardening/security-headers-x-frame-options/
- You can enable it by modifying your Apache settings or your
.htaccessfile - on server side
- You can enable it by modifying your Apache settings or your
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors
- https://docs.sucuri.net/warnings/hardening/security-headers-x-frame-options/
-
Missing security header to prevent Content Type sniffing.
- https://docs.sucuri.net/warnings/hardening/security-headers-x-content-type-nosniff/
- You can enable it by modifying your Apache settings or your
.htaccessfile - on server side
- You can enable it by modifying your Apache settings or your
- https://docs.sucuri.net/warnings/hardening/security-headers-x-content-type-nosniff/
-
Missing Strict-Transport-Security security header
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
- applicable only to HTTPS sites on Laddr, can it be configurable per Emergence instance/site?
- should be done on server side
-
Missing Content-Security-Policy directive.
- https://blog.sucuri.net/2018/04/content-security-policy.html
- We recommend to add the following CSP directives (you can use default-src if all values are the same): script-src, object-src, base-uri, frame-src
- try to block executing scripts added in content (i.e. page, buzz, project description, comment etc)
- Use "report-uri" to log failed requests. Endpoint to send report json to: https://report-uri.com/#prices (free up to 10.000 requests per month); when testing in production use "report-only" to send reports to URL endpoint what would be blocked by set CSP rules.
- https://blog.sucuri.net/2018/04/content-security-policy.html
-
Leaked PHP version. Your site is displaying your PHP version in the HTTP headers. Please set expose_php = Off.
- https://secure.php.net/manual/en/ini.core.php
- this should be done on server side (Emergence hosting)
Check full report at:
https://sitecheck.sucuri.net/results/codeforphilly.org (same results are for other Laddr instances)
- 主要言語
- Smarty
- スター
- 62
- フォーク
- 34
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
CodeForPhilly/laddr のほかの issue
-
難易度 3/5 1〜2日 初心者へのやさしさ 35/100
CodeForPhilly/laddr#256 ·
-
難易度 4/5 3〜5日 初心者へのやさしさ 35/100
CodeForPhilly/laddr#230 ·
-
easy win help wanted
難易度 3/5 1〜2日 初心者へのやさしさ 32/100
CodeForPhilly/laddr#228 · コメント 1 件 ·
-
easy win
難易度 4/5 3〜5日 初心者へのやさしさ 35/100
CodeForPhilly/laddr#224 · コメント 2 件 ·
-
Member Onboarding Questionnaire対応中かも @themightychris が 2457 日前に担当しました。 オープン
CodeForPhilly/laddr#219 · コメント 3 件 · リアクション 1 件 · 担当者 1 名 ·
CodeForPhilly/laddr の issue をすべて見る
似ている issue
-
🧠 Admin
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
Needs: Triage :mag: Product: Terraform (AVM) Topic: Networking (HS) :globe_with_meridians:
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
Azure/Azure-Landing-Zones#4299 · コメント 1 件 · リアクション 4 件 ·
メンテナーはふだん 4 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
terraform-google-modules/terraform-google-kubernetes-engine#2663 ·
メンテナーはふだん 2 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 66/100
Piwigo/piwigo-docker#18 ·
-
Controller pods on default limits CrashLoopBackOff and constantly reclaim memory対応中かも @brsmnv が今日担当しました。 オープンbug
難易度 2/5 1時間未満 初心者へのやさしさ 68/100
ironcore-dev/ironcore-net#560 ·
メンテナーはふだん 1 日以内に返信