Vitexus / FirefoxNightlyDeb

Debian package installing Firefox Nightly
https://www.mozilla.org/
BSD 2-Clause "Simplified" License
17 stars 9 forks source link

Hardenize Website #16

Open TNTBOMBOM opened 3 years ago

TNTBOMBOM commented 3 years ago

Its better for the visitors so as users to have secure path/browsing when they use vitex website/repo.

So here are some useful scanners to show useful reports on where the issues are:

https://www.hardenize.com/report/vitexsoftware.cz/1627479787 (many missing features) https://www.ssllabs.com/ssltest/analyze.html?d=www.vitexsoftware.cz&s=213.151.89.97 (B) https://securityheaders.com/?q=www.vitexsoftware.cz&followRedirects=on (F) https://observatory.mozilla.org/analyze/www.vitexsoftware.cz (F)

Important missing features/configs:

From ssllabs scanner:

https://www.ssllabs.com/ssltest/analyze.html?d=www.vitexsoftware.cz&s=213.151.89.97

We find:

Valid until | Tue, 22 Jun 2021 15:34:45 UTC (expired 1 month and 5 days ago)   EXPIRED

From Hardenize scanner

https://www.hardenize.com/report/vitexsoftware.cz/1627479787

We find:

https://www.hardenize.com/report/vitexsoftware.cz/1627479787#domain_caa

The provided certificate doesn't match the expected hostname.

Expected hostname: vitexsoftware.cz

https://www.hardenize.com/report/vitexsoftware.cz/1627479787#www_certs

https://www.hardenize.com/report/vitexsoftware.cz/1627479787#www_cookies

https://www.hardenize.com/report/vitexsoftware.cz/1627479787#www_hsts

https://www.hardenize.com/report/vitexsoftware.cz/1627479787#www_csp

https://www.hardenize.com/report/vitexsoftware.cz/1627479787#www_xfo https://www.hardenize.com/report/vitexsoftware.cz/1627479787#www_xxssp https://www.hardenize.com/report/vitexsoftware.cz/1627479787#www_xcto

From securityheaders

https://securityheaders.com/?q=www.vitexsoftware.cz&followRedirects=on

We find:

Everything is missing :) .


ThX!

Vitexus commented 3 years ago

Thank you for your issue.