Class: XspearScan::CallbackCheckHeaders
- Inherits:
-
ScanCallbackFunc
- Object
- ScanCallbackFunc
- XspearScan::CallbackCheckHeaders
- Defined in:
- lib/XSpear.rb
Instance Method Summary collapse
Methods inherited from ScanCallbackFunc
Constructor Details
This class inherits a constructor from XspearScan::ScanCallbackFunc
Instance Method Details
#run ⇒ Object
149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 |
# File 'lib/XSpear.rb', line 149 def run if !@response['Server'].nil? # Server header @report.add_issue("i","s","-","-","<original query>","Found Server: #{@response['Server']}") end if @response['Strict-Transport-Security'].nil? # HSTS @report.add_issue("i","s","-","-","<original query>","Not set HSTS") end if !@response['Content-Type'].nil? @report.add_issue("i","s","-","-","<original query>","Content-Type: #{@response['Content-Type']}") end if !@response['X-XSS-Protection'].nil? @report.add_issue("i","s","-","-","<original query>","Not set X-XSS-Protection") end if !@response['X-Frame-Options'].nil? @report.add_issue("i","s","-","-","<original query>","X-Frame-Options: #{@response['X-Frame-Options']}") else @report.add_issue("l","s","-","-","<original query>","Not Set X-Frame-Options") end if !@response['Content-Security-Policy'].nil? begin csp = @response['Content-Security-Policy'] csp = csp.split(';') r = " " csp.each do |c| d = c.split " " r = r+d[0]+" " end @report.add_issue("i","s","-","-","<original query>","Enabled CSP") rescue @report.add_issue("i","s","-","-","<original query>","CSP ERROR") end else @report.add_issue("m","s","-","-","<original query>","Not Set CSP") end [false, "not reflected #{@query}"] end |