Headers HTTP Seguros en Apache
blessedc0de
sudo a2enmod headers
sudo apachectl -M
sudo nvim /etc/apache2/conf-available/security.conf
Header always set X-Xss-Protection "1; mode=block" Header always set X-Content-Type-Options: nosniff Header always set X-Frame-Options "SAMEORIGIN" Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" Header always set Content-Security-Policy "default-src 'self'; font-src *;img-src * data:; script-src *; style-src *;" Header always set Referrer-Policy "strict-origin" Header always set Permissions-Policy "geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()"
sudo systemctl restart apache2 ... https://www.youtube.com/watch?v=B7ayKlXpnPk
2022-12-14
0.0 LBC
Copyrighted (contact publisher)
3950811 Bytes