Http Missing Strict Transport Security
Description
Detects when a website served over HTTPS is missing the HTTP Strict Transport Security (HSTS) header. HSTS is a critical security header that forces browsers to only connect over HTTPS, preventing downgrade attacks and protecting against SSL-stripping.
Weakness:
131 - Insecure or unset HTTP headers - Strict Transport Security
Category: Protocol Manipulation
Detection Strategy
• Website must be accessed over HTTPS (https:// URL scheme)
• The Strict-Transport-Security header is not present in the HTTP response
• Reports a vulnerability when both conditions are true - HTTPS site without HSTS header
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.