blob: e62fa573062bd6f81ddc7e4cd3a848f2bd50e092 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
|
#!/usr/bin/env bash
# Check important deployed security headers and PHP session cookie flags.
set -u
fail=0
check_contains() {
local name="$1"
local haystack="$2"
local needle="$3"
if printf '%s' "$haystack" | grep -Fqi "$needle"; then
printf 'OK: %s\n' "$name"
else
printf 'FAIL: %s missing %s\n' "$name" "$needle" >&2
fail=1
fi
}
check_not_contains() {
local name="$1"
local haystack="$2"
local needle="$3"
if printf '%s' "$haystack" | grep -Fqi "$needle"; then
printf 'FAIL: %s contains %s\n' "$name" "$needle" >&2
fail=1
else
printf 'OK: %s\n' "$name"
fi
}
fetch_headers() {
local host="$1"
local path="$2"
curl -skI --resolve "${host}:443:127.0.0.1" "https://${host}${path}"
}
www_headers="$(fetch_headers www.sillylaird.ca /)"
# Session cookies are only set on pages that start a session (admin login, admin panel).
admin_headers="$(fetch_headers www.sillylaird.ca /admin/login.php)"
guestbook_headers="$(fetch_headers guestbook.sillylaird.ca /form.php)"
check_contains "www cookie Secure" "$admin_headers" "set-cookie: PHPSESSID="
check_contains "www cookie Secure" "$admin_headers" "secure"
check_contains "www cookie HttpOnly" "$admin_headers" "httponly"
check_contains "www cookie SameSite" "$admin_headers" "samesite=lax"
check_contains "www HSTS" "$www_headers" "strict-transport-security:"
check_contains "www nosniff" "$www_headers" "x-content-type-options: nosniff"
check_contains "www CSP" "$www_headers" "content-security-policy:"
check_contains "www CSP frame policy" "$www_headers" "frame-ancestors 'none'"
check_not_contains "www server version" "$www_headers" "nginx/"
check_contains "guestbook cookie Secure" "$guestbook_headers" "set-cookie: PHPSESSID="
check_contains "guestbook cookie Secure" "$guestbook_headers" "secure"
check_contains "guestbook cookie HttpOnly" "$guestbook_headers" "httponly"
check_contains "guestbook cookie SameSite" "$guestbook_headers" "samesite=lax"
check_contains "guestbook HSTS" "$guestbook_headers" "strict-transport-security:"
check_contains "guestbook nosniff" "$guestbook_headers" "x-content-type-options: nosniff"
check_contains "guestbook CSP frame policy" "$guestbook_headers" "frame-ancestors https://www.sillylaird.ca"
check_not_contains "guestbook server version" "$guestbook_headers" "nginx/"
exit "$fail"
|