HTTP Strict Transport Policy not enabled on newly made accounts

Disclosed: 2014-10-03 23:38:52 By shahmeer-amir To slack
Unknown
Vulnerability Details
Hey As we know that the HSTS prevents MITM against SSL. I just checked the headers of the account i created localhost.slack.com SERVER RESPONSE: 200 OK Cache-Control: private, no-cache, no-store, must-revalidate Content-Encoding: gzip Content-Type: text/html; charset="utf-8" Date: Wed, 03 Sep 2014 00:45:35 GMT Expires: Mon, 26 Jul 1997 05:00:00 GMT Pragma: no-cache Server: Apache Vary: Accept-Encoding X-Frame-Options: SAMEORIGIN X-Robots-Tag: noindex,nofollow X-XSS-Protection: 0 Content-Length: 4606 Connection: keep-alive The HSTS is not set here. Awaiting your reply
Actions
View on HackerOne
Report Stats
  • Report ID: 26763
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report