Hardening Improvements - security header recommendations
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 25/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Cần làm rõ
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- apache, php
- Lĩnh vực
- infrastructure, security
Hướng nghiên cứu
Bắt đầu bằng cách xem lại các thiết lập Apache hoặc cấu hình .htaccess được đề cập trong issue và xác định những security header nào do dịch vụ hosting Emergence kiểm soát và những header nào do instance Laddr kiểm soát. Kiểm tra cách các site HTTPS được cấu hình và liệu PHP có để lộ phiên bản của nó hay không. Được xem là hoàn tất khi các header áp dụng và thiết lập PHP được bật mà không làm hỏng các site hiện có.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Some recommendations from Sucuri:
-
Missing security header for ClickJacking Protection. Alternatively, you can use Content-Security-Policy: frame-ancestors 'none'.
- https://docs.sucuri.net/warnings/hardening/security-headers-x-frame-options/
- You can enable it by modifying your Apache settings or your
.htaccessfile - on server side
- You can enable it by modifying your Apache settings or your
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors
- https://docs.sucuri.net/warnings/hardening/security-headers-x-frame-options/
-
Missing security header to prevent Content Type sniffing.
- https://docs.sucuri.net/warnings/hardening/security-headers-x-content-type-nosniff/
- You can enable it by modifying your Apache settings or your
.htaccessfile - on server side
- You can enable it by modifying your Apache settings or your
- https://docs.sucuri.net/warnings/hardening/security-headers-x-content-type-nosniff/
-
Missing Strict-Transport-Security security header
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
- applicable only to HTTPS sites on Laddr, can it be configurable per Emergence instance/site?
- should be done on server side
-
Missing Content-Security-Policy directive.
- https://blog.sucuri.net/2018/04/content-security-policy.html
- We recommend to add the following CSP directives (you can use default-src if all values are the same): script-src, object-src, base-uri, frame-src
- try to block executing scripts added in content (i.e. page, buzz, project description, comment etc)
- Use "report-uri" to log failed requests. Endpoint to send report json to: https://report-uri.com/#prices (free up to 10.000 requests per month); when testing in production use "report-only" to send reports to URL endpoint what would be blocked by set CSP rules.
- https://blog.sucuri.net/2018/04/content-security-policy.html
-
Leaked PHP version. Your site is displaying your PHP version in the HTTP headers. Please set expose_php = Off.
- https://secure.php.net/manual/en/ini.core.php
- this should be done on server side (Emergence hosting)
Check full report at:
https://sitecheck.sucuri.net/results/codeforphilly.org (same results are for other Laddr instances)
- Ngôn ngữ chính
- Smarty
- Star
- 62
- Fork
- 34
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của CodeForPhilly/laddr
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 35/100
CodeForPhilly/laddr#256 ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
CodeForPhilly/laddr#230 ·
-
easy win help wanted
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 32/100
CodeForPhilly/laddr#228 · 1 bình luận ·
-
easy win
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
CodeForPhilly/laddr#224 · 2 bình luận ·
-
Member Onboarding QuestionnaireCó thể đã có người làm @themightychris đã nhận 2460 ngày trước. Đang mở
CodeForPhilly/laddr#219 · 3 bình luận · 1 reaction · 1 người được giao ·
Tất cả issue của CodeForPhilly/laddr
Issue tương tự
-
Update Python support to 3.15Đang mởpython-version
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
-
initramfs: -type f (#18686) skips the libcurl.so.4 symlink, libcurl no longer copied into initramfsĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 2 ngày
-
bug triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
FairwindsOps/nova#484 ·
-
CI
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
AR-js-org/arjs-plugin-artoolkit#69 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
louislam/uptime-kuma#7956 · 4 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày