aboutsummaryrefslogtreecommitdiffstats
path: root/tools/security_check.sh
blob: e62fa573062bd6f81ddc7e4cd3a848f2bd50e092 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
#!/usr/bin/env bash
# Check important deployed security headers and PHP session cookie flags.

set -u

fail=0

check_contains() {
  local name="$1"
  local haystack="$2"
  local needle="$3"
  if printf '%s' "$haystack" | grep -Fqi "$needle"; then
    printf 'OK: %s\n' "$name"
  else
    printf 'FAIL: %s missing %s\n' "$name" "$needle" >&2
    fail=1
  fi
}

check_not_contains() {
  local name="$1"
  local haystack="$2"
  local needle="$3"
  if printf '%s' "$haystack" | grep -Fqi "$needle"; then
    printf 'FAIL: %s contains %s\n' "$name" "$needle" >&2
    fail=1
  else
    printf 'OK: %s\n' "$name"
  fi
}

fetch_headers() {
  local host="$1"
  local path="$2"
  curl -skI --resolve "${host}:443:127.0.0.1" "https://${host}${path}"
}

www_headers="$(fetch_headers www.sillylaird.ca /)"
# Session cookies are only set on pages that start a session (admin login, admin panel).
admin_headers="$(fetch_headers www.sillylaird.ca /admin/login.php)"
guestbook_headers="$(fetch_headers guestbook.sillylaird.ca /form.php)"

check_contains "www cookie Secure" "$admin_headers" "set-cookie: PHPSESSID="
check_contains "www cookie Secure" "$admin_headers" "secure"
check_contains "www cookie HttpOnly" "$admin_headers" "httponly"
check_contains "www cookie SameSite" "$admin_headers" "samesite=lax"
check_contains "www HSTS" "$www_headers" "strict-transport-security:"
check_contains "www nosniff" "$www_headers" "x-content-type-options: nosniff"
check_contains "www CSP" "$www_headers" "content-security-policy:"
check_contains "www CSP frame policy" "$www_headers" "frame-ancestors 'none'"
check_not_contains "www server version" "$www_headers" "nginx/"

check_contains "guestbook cookie Secure" "$guestbook_headers" "set-cookie: PHPSESSID="
check_contains "guestbook cookie Secure" "$guestbook_headers" "secure"
check_contains "guestbook cookie HttpOnly" "$guestbook_headers" "httponly"
check_contains "guestbook cookie SameSite" "$guestbook_headers" "samesite=lax"
check_contains "guestbook HSTS" "$guestbook_headers" "strict-transport-security:"
check_contains "guestbook nosniff" "$guestbook_headers" "x-content-type-options: nosniff"
check_contains "guestbook CSP frame policy" "$guestbook_headers" "frame-ancestors https://www.sillylaird.ca"
check_not_contains "guestbook server version" "$guestbook_headers" "nginx/"

exit "$fail"