Recommendations for X-XSS-Protection , X-Frame-Options, X-Content-Type nosniff
-
After preforming a Malware Scan, which resulted in Clean across the board, under “Website Details” tab there is a section “Recommendations for the site” which has the following:
======
Security Header: X-XSS-Protection Missing
We did not find the recommended security header for XSS Protection on your site.
https://kb.sucuri.net/warnings/hardening/headers-x-xss-protectionSecurity Header: X-Frame-Options
We did not find the recommended security header for ClickJacking Protection on your site.
https://kb.sucuri.net/warnings/hardening/headers-x-frame-clickjackingSecurity Header: X-Content-Type nosniff
We did not find the recommended security header to prevent Content Type sniffing on your site.
https://kb.sucuri.net/warnings/hardening/headers-x-content-typeServer Banners Displayed
Your site is displaying your Apache web server default banners.
https://kb.sucuri.net/warnings/hardening/disable-server-banners
========These recommendations are fine, but when following the links, it states “it is recommended that you add the following header to your site”, but it does not instruct one HOW or WHERE to insert these in the Header of the site.
Are they supposed to go within meta-tags?Could you please elucidate further?
Thank you.
- The topic ‘Recommendations for X-XSS-Protection , X-Frame-Options, X-Content-Type nosniff’ is closed to new replies.