Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
F-2024-0007·configuration

Strict-Transport-Security not enforced

Acknowledgedpentestblackboxnextjs
TL;DR

The site did not return an HSTS header, leaving the browser without protection against protocol downgrade or SSL-stripping attempts on hostile networks.

Severity
INFO
Impact
LOW
Likelihood
LOW
Method
MManual review
CAT.
Complexity
LOW
Exploitability
LOW
02Section · Description

Description

Responses did not include the Strict-Transport-Security header. Without HSTS, browsers do not enforce HTTPS-only access on first visit or after the policy expires, widening the window for SSL-stripping or downgrade attacks.

03Section · Impact

Impact

Informational. Defense-in-depth gap rather than a directly exploitable bug.

04Section · Recommendation

Recommendation

Return Strict-Transport-Security: max-age=63072000; includeSubDomains; preload on all responses. Consider HSTS preload submission once the policy has been stable for a few weeks.

Dedprz: Acknowledged. Zealynx: Acknowledged.

F-2024-0007