Criptographic Issue: Strisct Transport Security with not good max age..(TOO SHORT!)
Unknown
Vulnerability Details
Hello again team of Localize!
I have already reported this bug to the HackerOne team..and they fix it..not immediately, because it's low priority but they fix it!
Report: https://hackerone.com/reports/3709 :))
Issue: Strict Transport Security with too short max age.
Description: Your site use a good "Strict Transport Security" but with short MAX AGE!
Severity: See more information below.
Proof of Concept by ssllabs.com (100% affidability):
http://grabilla.com/04416-ffdc6c21-b92b-45e6-8a41-36cf650bc2f2.html
"Strict Transport Security (HSTS) Yes max-age=1209600 TOO SHORT (less than 180 days)"
If you want to see the full scan with your "eyes" check it here: https://www.ssllabs.com/ssltest/analyze.html?d=localize.im&s=217.70.186.107
Also..See more information here:
https://community.qualys.com/thread/10857
Thanks and best regards,
Simone
Actions
View on HackerOneReport Stats
- Report ID: 9008
- State: Closed
- Substate: resolved
- Upvotes: 3