All-in-one free web application security tool. Web application vulnerability and privacy scanner with support for HTTP cookies, Flash, HTML5 localStorage, sessionStorage, CANVAS, Supercookies, Evercookies. Includes a free SSL/TLS, HTML and HTTP vulnerability scanner and URL malware scanner.
Category: Social Network CDN Resource
Keywords: apps data make share users people policy account content cookies privacy provide facebook policies services companies including statement advertising information
Last fetched: 2019-05-20T11:11:57.855214+00:00
HTTP status: 5 Sub-resource URL
A non-standard but widely accepted header introduced originally by Microsoft to disable "content sniffing" or heuristic content type discovery in absence or mismatch of a proper HTTP
Content-Type declaration, which led to a number of web attacks. In general, presence of the header with its only defined value of
nosniff is considered as part of a properly secured HTTP response.
Fuzzy content type guessing is disabled+1
XmlHttpRequest from a website that is not in the same origin, which is a precaution against various types of data stealing attacks. The target server has to explicitly allow the origin domain using the
Access-Control-Allow-Origin (ACAO) header, or it may allow all origins to access it using a wildcard
*. The latter however creates a potential security issue if the website in question is transactional and processing sensitive data, so the wildcard should be only used on websites consciously offering public APIs.
The header sets permissive AJAX access by using wildcard origin
*. It may be OK if the website is a publicly accessible REST API but otherwise it should be not present at all
Transport Layer Security (TLS) is enabled+2
X-Frame-Options header is missing
X-XSS-Protection header is missing
default-src https: data: wss: blob: chrome-extension: 'unsafe-inline' 'unsafe-eval';report-uri https://www.facebook.com/csp/reporting/;
base-uri allows attackers to inject
base tags which override the base URI to an attacker-controlled origin. Set to
'none' unless you need to handle tricky relative URLs scheme
block-all-mixed-content directive if your website is only accessible over TLS and you are certain it doesn not have any legacy plaintext resources. Otherwise you may add adding
upgrade-insecure-requests directive if your website may still have some legacy plaintext HTTP resources and you want them to be still available rather than blocked
default-src data: origin allows bypassing CSP and execution of inlined untrusted scripts
default-src 'unsafe-inline' allows bypassing of CSP and execution of inlined untrusted scripts. Use
default-src 'unsafe-eval' allows bypassing of CSP and execution of inlined untrusted scripts. Use
Want second opinion? Try Google CSP Evaluator.