Nikto Apache Findings
- by Vince
-
in Blog
-
Hits: 2135
AWS Lightsail makes it (too) easy to fire up a new server, install an application, and let it loose on the Internet. You have to learn somewhere and that's as good as any place but let's do a little housecleaning on the default apache2.conf file.
If we scan our stock apache server, we get some errors:
+ Server leaks inodes via ETags, header found with file /, fields: 0xb3
+ The anti-clickjacking X-Frame-Options header is not present.
+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
+ The site uses SSL and the Strict-Transport-Security HTTP header is not defined.
+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type