Overview
Security headers are cheap defence in depth. Without a Content-Security-Policy an XSS bug becomes full account takeover; without X-Frame-Options or frame-ancestors the page is clickjackable; without HSTS a first visit can be downgraded.\nEach header closes a whole class of client-side attacks rather than a single bug.
Indicators of Compromise
Signals that suggest this is present on a system.
- No Content-Security-Policy response header
- Missing Strict-Transport-Security
- Page renderable inside an iframe
Controls that stop it
-
Harden TLS and Security Headers
Serve everything over TLS with HSTS so downgrades are impossible, set a modern Content-Security-Policy, enable HSTS preload, deny framing with frame-ancestors, and switch on Referrer-Policy and Permissions-Policy. Disable unused legacy protocols and cipher suites rather than leaving them configured for compatibility.