HSTS Missing From HTTPS Server (RFC 6797)
Plugin ID: 142960
Port: tcp/443
The remote web server is not enforcing HSTS, as defined by RFC 6797.
HSTS is an optional response header that can be configured on the server to instruct
the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks,
SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking protections.
Javasolt megoldás
Configure the remote web server to use HSTS.
Web Server HTTP Header Internal IP Disclosure
This may expose internal IP addresses that are usually hidden or
masked behind a Network Address Translation (NAT) Firewall or proxy
server.
There is a known issue with Microsoft IIS 4.0 doing this in its default
configuration. This may also affect other web servers, web applications,
web proxies, load balancers and through a variety of misconfigurations
related to redirection.
Javasolt megoldás
Apply configuration suggested by vendor.