Jonathan Hodgson
|
e247c85bc9
|
BIN: analyse-headers: read from stdin if first arg is -
This makes testing much easier
|
2020-12-09 16:24:59 +00:00 |
|
Jonathan Hodgson
|
cad2f2d2d5
|
BIN: analyse-headers: Add more notes to expect-ct description
As pointed out by <Dom Ingram>, the expect-ct is likely to become
obsolete in June 2012
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Expect-CT
|
2020-12-09 16:13:39 +00:00 |
|
Jonathan Hodgson
|
7ea1e9a964
|
BIN: analyse-headers: Fix incorrect reporting of SSL issues
It turns out the SSL flags secure and httponly are not case sensitive.
https://tools.ietf.org/html/rfc6265#section-5.2.5
I cannot find any documentation about the SameSite=Strict so I will
leave it case sensitive for now. The spec for that section is here:
https://tools.ietf.org/html/draft-ietf-httpbis-rfc6265bis-05#section-5.2
Thanks <Dom Ingram> for flagging this
|
2020-12-09 16:08:26 +00:00 |
|
Jonathan Hodgson
|
7a7ffc608d
|
BIN: analyse-headers: add expect-ct and start referrer-policy
|
2020-12-03 11:19:35 +00:00 |
|
Jonathan Hodgson
|
3ce547a0b2
|
BIN: Analyse-headers: Adds to description for cookie flag
|
2020-12-02 10:54:10 +00:00 |
|
Jonathan Hodgson
|
fb5774a584
|
BIN: analyse-headers: fix error "wrap command not found"
|
2020-12-02 09:19:47 +00:00 |
|
Jonathan Hodgson
|
9ef36af8f7
|
BIN: analyse-headers: adds feature-policy and permissions-policy checks
|
2020-12-02 09:11:52 +00:00 |
|
Jonathan Hodgson
|
61097006a4
|
BIN: analyse-headers: Wrap text in descriptions
The text in descriptions is now wrapped to 80 chars. This does not
affect the headers printed at the top which are not wrapped
|
2020-12-02 08:32:10 +00:00 |
|
Jonathan Hodgson
|
af81ccd62e
|
BIN: Adds SameSite check in analyse-headers script
The script will now warn you if the SameSite option is not set to Strict
on cookies.
|
2020-12-01 21:17:34 +00:00 |
|
Jonathan Hodgson
|
1f29c17ab5
|
BIN: Fix webtest script when : in cookies
If there was a colon in a cookie, the script would misidentify insecure
cookie configurations
|
2020-12-01 19:56:33 +00:00 |
|
Jonathan Hodgson
|
a3f75d9b32
|
BIN: Adds analyse-headers script
The script is in early stages of development but should work for some of
the most common mis-configurtaions.
|
2020-12-01 18:15:01 +00:00 |
|
Jonathan Hodgson
|
ad03136de5
|
Adds scripts to help with ssl testing
|
2020-09-22 15:49:42 +01:00 |
|
Jonathan Hodgson
|
af04f665cd
|
Renames jwtcat to catjwt to avoid clash with 3rd party tool
|
2020-09-22 15:41:06 +01:00 |
|
Jonathan Hodgson
|
c5fd08bb76
|
Creates script for printing jwt web tokens
|
2020-09-22 15:40:20 +01:00 |
|
Jonathan Hodgson
|
3ba3ca03b5
|
A start to webtest script
|
2020-09-19 11:18:55 +01:00 |
|
Jonathan Hodgson
|
74578ef182
|
Adds getpaths script
|
2020-07-29 17:34:17 +01:00 |
|
Jonathan Hodgson
|
b8fad36f8d
|
changed profile name to headless
|
2020-05-25 18:29:18 +01:00 |
|
Jonathan Hodgson
|
34ea59f0f6
|
Will create firefox profile
|
2020-05-25 18:13:43 +01:00 |
|
Jonathan Hodgson
|
c21d54d9a4
|
Adds help and checks url is given
|
2020-05-25 18:04:55 +01:00 |
|
Jonathan Hodgson
|
518d11f4ce
|
Makes clickjacking script look for ff dev edition
|
2020-05-25 17:56:29 +01:00 |
|
Jonathan Hodgson
|
45ac26d2d7
|
Adds script to make clickjacking screenshot
|
2020-05-25 17:48:56 +01:00 |
|
Jonathan Hodgson
|
121798e075
|
Lots of bin changes
|
2020-01-04 13:21:05 +00:00 |
|
Jonathan Hodgson
|
a01077a8e9
|
Adds a script for turning an html form into a curl requst
|
2019-12-17 12:30:12 +00:00 |
|