Criptographic Issue: Strisct Transport Security with not good max age..(TOO SHORT!)

Disclosed: 2014-04-23 03:19:51 By simon90 To localize
Unknown
Vulnerability Details
Hello again team of Localize! I have already reported this bug to the HackerOne team..and they fix it..not immediately, because it's low priority but they fix it! Report: https://hackerone.com/reports/3709 :)) Issue: Strict Transport Security with too short max age. Description: Your site use a good "Strict Transport Security" but with short MAX AGE! Severity: See more information below. Proof of Concept by ssllabs.com (100% affidability): http://grabilla.com/04416-ffdc6c21-b92b-45e6-8a41-36cf650bc2f2.html "Strict Transport Security (HSTS) Yes max-age=1209600 TOO SHORT (less than 180 days)" If you want to see the full scan with your "eyes" check it here: https://www.ssllabs.com/ssltest/analyze.html?d=localize.im&s=217.70.186.107 Also..See more information here: https://community.qualys.com/thread/10857 Thanks and best regards, Simone
Actions
View on HackerOne
Report Stats
  • Report ID: 9008
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report