diff options
| author | sillylaird <sillyfanboy@gmail.com> | 2026-09-03 00:33:59 +0000 |
|---|---|---|
| committer | sillylaird <sillyfanboy@gmail.com> | 2026-09-03 00:33:59 +0000 |
| commit | 898b52edcb47bcb3e9d6106e74ca73e74ea01e70 (patch) | |
| tree | 85c6ee5ad58b860144551184d4cf86b560c62b91 /tools/security_check.sh | |
| download | www-main.tar.gz www-main.zip | |
Diffstat (limited to 'tools/security_check.sh')
| -rwxr-xr-x | tools/security_check.sh | 62 |
1 files changed, 62 insertions, 0 deletions
diff --git a/tools/security_check.sh b/tools/security_check.sh new file mode 100755 index 0000000..e62fa57 --- /dev/null +++ b/tools/security_check.sh @@ -0,0 +1,62 @@ +#!/usr/bin/env bash +# Check important deployed security headers and PHP session cookie flags. + +set -u + +fail=0 + +check_contains() { + local name="$1" + local haystack="$2" + local needle="$3" + if printf '%s' "$haystack" | grep -Fqi "$needle"; then + printf 'OK: %s\n' "$name" + else + printf 'FAIL: %s missing %s\n' "$name" "$needle" >&2 + fail=1 + fi +} + +check_not_contains() { + local name="$1" + local haystack="$2" + local needle="$3" + if printf '%s' "$haystack" | grep -Fqi "$needle"; then + printf 'FAIL: %s contains %s\n' "$name" "$needle" >&2 + fail=1 + else + printf 'OK: %s\n' "$name" + fi +} + +fetch_headers() { + local host="$1" + local path="$2" + curl -skI --resolve "${host}:443:127.0.0.1" "https://${host}${path}" +} + +www_headers="$(fetch_headers www.sillylaird.ca /)" +# Session cookies are only set on pages that start a session (admin login, admin panel). +admin_headers="$(fetch_headers www.sillylaird.ca /admin/login.php)" +guestbook_headers="$(fetch_headers guestbook.sillylaird.ca /form.php)" + +check_contains "www cookie Secure" "$admin_headers" "set-cookie: PHPSESSID=" +check_contains "www cookie Secure" "$admin_headers" "secure" +check_contains "www cookie HttpOnly" "$admin_headers" "httponly" +check_contains "www cookie SameSite" "$admin_headers" "samesite=lax" +check_contains "www HSTS" "$www_headers" "strict-transport-security:" +check_contains "www nosniff" "$www_headers" "x-content-type-options: nosniff" +check_contains "www CSP" "$www_headers" "content-security-policy:" +check_contains "www CSP frame policy" "$www_headers" "frame-ancestors 'none'" +check_not_contains "www server version" "$www_headers" "nginx/" + +check_contains "guestbook cookie Secure" "$guestbook_headers" "set-cookie: PHPSESSID=" +check_contains "guestbook cookie Secure" "$guestbook_headers" "secure" +check_contains "guestbook cookie HttpOnly" "$guestbook_headers" "httponly" +check_contains "guestbook cookie SameSite" "$guestbook_headers" "samesite=lax" +check_contains "guestbook HSTS" "$guestbook_headers" "strict-transport-security:" +check_contains "guestbook nosniff" "$guestbook_headers" "x-content-type-options: nosniff" +check_contains "guestbook CSP frame policy" "$guestbook_headers" "frame-ancestors https://www.sillylaird.ca" +check_not_contains "guestbook server version" "$guestbook_headers" "nginx/" + +exit "$fail" |
