HTTP Strict Transport Policy not enabled on newly made accounts
Unknown
Vulnerability Details
Hey
As we know that the HSTS prevents MITM against SSL. I just checked the headers of the account i created localhost.slack.com
SERVER RESPONSE: 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Content-Encoding: gzip
Content-Type: text/html; charset="utf-8"
Date: Wed, 03 Sep 2014 00:45:35 GMT
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Server: Apache
Vary: Accept-Encoding
X-Frame-Options: SAMEORIGIN
X-Robots-Tag: noindex,nofollow
X-XSS-Protection: 0
Content-Length: 4606
Connection: keep-alive
The HSTS is not set here.
Awaiting your reply
Actions
View on HackerOneReport Stats
- Report ID: 26763
- State: Closed
- Substate: resolved
- Upvotes: 2