Security headers
HTTP security headers are declarative defenses: the server tells the browser how to behave to mitigate XSS, clickjacking, HTTP downgrade, MIME sniffing, information leakage and origin isolation. Their absence isn’t a flaw by itself, but it enables or worsens other vulnerabilities, so they’re a mandatory part of any audit.
Threat model
Section titled “Threat model”Without the right headers, a reflected XSS exploits frictionlessly, a page can be framed
(clickjacking), traffic downgrades to HTTP (MITM/SSL stripping), tokens leak via Referer,
and uploaded content is interpreted as executable.
Catalog (what each one stops and recommended value)
Section titled “Catalog (what each one stops and recommended value)”Content-Security-Policy (CSP)
Section titled “Content-Security-Policy (CSP)”Controls where resources load from and which scripts run: defense in depth against XSS
and exfiltration. Prefer nonce/hash + strict-dynamic (see XSS page).
Content-Security-Policy: default-src 'self'; script-src 'nonce-RAND' 'strict-dynamic'; object-src 'none'; base-uri 'none'; frame-ancestors 'none'Strict-Transport-Security (HSTS)
Section titled “Strict-Transport-Security (HSTS)”Forces HTTPS in the browser, prevents downgrade and SSL stripping. With preload,
the browser doesn’t even try HTTP the first time.
Strict-Transport-Security: max-age=63072000; includeSubDomains; preloadAnti-clickjacking
Section titled “Anti-clickjacking”CSP frame-ancestors (modern) and X-Frame-Options (compatibility).
Content-Security-Policy: frame-ancestors 'none'X-Frame-Options: DENYX-Content-Type-Options
Section titled “X-Content-Type-Options”Prevents MIME sniffing (the browser guessing the type and running as script something uploaded as an image).
X-Content-Type-Options: nosniffReferrer-Policy
Section titled “Referrer-Policy”Limits URL (and in-URL token) leakage via the Referer header.
Referrer-Policy: strict-origin-when-cross-originPermissions-Policy
Section titled “Permissions-Policy”Restricts powerful browser APIs (camera, mic, geolocation, USB…).
Permissions-Policy: geolocation=(), camera=(), microphone=(), payment=()Origin isolation (COOP / COEP / CORP)
Section titled “Origin isolation (COOP / COEP / CORP)”Protect against cross-origin and side-channel attacks (Spectre) and enable
high-precision APIs. Cross-Origin-Opener-Policy, Cross-Origin-Embedder-Policy,
Cross-Origin-Resource-Policy.
Cookies (flags and prefixes)
Section titled “Cookies (flags and prefixes)”Set-Cookie: sid=...; HttpOnly; Secure; SameSite=Lax# Prefixes the browser enforces:__Host-sid=...; Secure; Path=/ # that host only, no Domain__Secure-sid=...; SecureOthers
Section titled “Others”Cache-Control: no-store on pages with sensitive data; Clear-Site-Data on logout.
Red Team
Section titled “Red Team”Assess what’s missing and leverage it: no CSP → trivial XSS; no frame-ancestors →
clickjacking; no HSTS → downgrade/MITM; lax Referer → token leakage; no nosniff → XSS
via uploaded content. Tools: securityheaders.com, Mozilla Observatory, nuclei,
and Burp.
Blue Team
Section titled “Blue Team”Recommended set (summary)
Section titled “Recommended set (summary)”Apply all of the above; CSP first in Report-Only to measure before enforcing;
__Host- for session cookies; no-store on sensitive data.
Detection
Section titled “Detection”Periodic header scanning across all hosts (not just the home page); alert if missing in
production or if a CSP includes unsafe-inline/unsafe-eval.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- Usually not a CVE: they’re configuration. Their absence has turned theoretical XSS/clickjacking into exploitable in countless audits and bug-bounty programs, and is a common observation in compliance reports (PCI, ENS).
Testing checklist
Section titled “Testing checklist”- CSP present and robust (no
unsafe-inline), evaluated with CSP Evaluator. - HSTS (ideally with
preload),X-Content-Type-Options: nosniff. -
frame-ancestors/X-Frame-Options. -
Referrer-PolicyandPermissions-Policy. - Cookie flags and prefixes (
HttpOnly/Secure/SameSite/__Host-). -
Cache-Control: no-storeon pages with sensitive data.