<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP Security Header Not Detected in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307593#M57933</link>
    <description>&lt;P&gt;Interestingly, there doesn't seem to be a way to reverse it when editing the question. I'll bring this up to the developers of the site to look into this. I've granted @Hidebrando karma points as buffer if/when there is an accepted answer on this question. &lt;/P&gt;

&lt;P&gt;Thanks for pointing it out @nickhillscpl and @jkat54 for the suggestion &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Feb 2018 01:27:26 GMT</pubDate>
    <dc:creator>ppablo</dc:creator>
    <dc:date>2018-02-08T01:27:26Z</dc:date>
    <item>
      <title>HTTP Security Header Not Detected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307588#M57928</link>
      <description>&lt;P&gt;Durante o scan de vulnerabilidades identificamos o seguinte issue HTTP Security Header Not Detected no agent do splunk universal-forwarder port 8089.&lt;/P&gt;

&lt;P&gt;Quero saber como corrigir este issue encontrado pelo scanner Qualys.&lt;BR /&gt;
Detalhes no arquivo em anexo.&lt;/P&gt;

&lt;P&gt;[Edit: Added translation]&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;During the vulnerability scan we have identified the following HTTP Security Header Not Detected issue in the splunk universal-forwarder port 8089 agent.&lt;BR /&gt;
I want to know how to fix this issue found by the Qualys scanner.&lt;BR /&gt;
Details in attached file&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2018 11:54:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307588#M57928</guid>
      <dc:creator>Hidebrando</dc:creator>
      <dc:date>2018-01-16T11:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Security Header Not Detected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307589#M57929</link>
      <description>&lt;P&gt;THREAT: This QID reports the absence of the following HTTP headers according to CWE-693: Protection Mechanism Failure: X-Frame-Options: This HTTP response header improves the protection of web applications against clickjacking attacks. Clickjacking, also known as a "UI redress attack", allows an attacker to use multiple transparent or opaque layers to trick a targeted user into clicking on a button or link on another page when they were intending to click on the the top level page.  X-XSS-Protection: This HTTP header enables the browser built-in Cross-Site Scripting (XSS) filter to prevent cross-site scripting attacks. X-XSS-Protection: 0; disables this functionality. X-Content-Type-Options: This HTTP header prevents attacks based on MIME-type mismatch. The only possible value is nosniff. If your server returns X-Content-Type-Options: nosniff in the response, the browser will refuse to load the styles and scripts in case they have an incorrect MIME-type.  Content-Security-Policy: This HTTP header helps to detect and mitigate certain types of attacks, including Cross Site Scripting (XSS), packet sniffing attacks and data injection attacks. Strict-Transport-Security: The HTTP Strict-Transport-Security response header (HSTS) is a security feature that lets a web site tell browsers that it should only be communicated with using HTTPS, instead of using HTTP. QID Detection Logic: This unauthenticated QID looks for the presence of the following HTTP responses: Valid directives for X-Frame-Options are: X-Frame-Options: DENY - The page cannot be displayed in a frame, regardless of the site attempting to do so. X-Frame-Options: SAMEORIGIN - The page can only be displayed in a frame on the same origin as the page itself. X-Frame-Options: ALLOW-FROM RESOURCE-URL - The page can only be displayed in a frame on the specified origin. Content-Security-Policy: frame-ancestors - This directive specifies valid parents that may embed a page using frame, iframe, object, embed, or applet Valid directives for X-XSS-Protections are: X-XSS-Protection: 1 - Enables XSS filtering (usually default in browsers). If a cross-site scripting attack is detected, the browser will sanitize the page (remove the unsafe parts). X-XSS-Protection: 1; mode=block - Enables XSS filtering. Rather than sanitizing the page, the browser will prevent rendering of the page if an attack is detected. X-XSS-Protection: 1; report=URI - Enables XSS filtering. If a cross-site scripting attack is detected, the browser will sanitize the page and report the violation. This uses the functionality of the CSP report-uri directive to send a report. X-XSS-Protection: 0 disables this directive and hence is also treated as not detected. A valid directive for X-Content-Type-Options: nosniff A valid directive for Content-Security-Policy: ;  A valid HSTS directive Strict-Transport-Security: max-age=; [; includeSubDomains][; preload] NOTE: All report-only directives (where applicable) are considered invalid.&lt;BR /&gt;
IMPACT: Depending on the vulnerability being exploited, an unauthenticated remote attacker could conduct cross-site scripting, clickjacking or MIME-type sniffing attacks.&lt;BR /&gt;
SOLUTION: CWE-693: Protection Mechanism Failure mentions the following - The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2018 13:29:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307589#M57929</guid>
      <dc:creator>Hidebrando</dc:creator>
      <dc:date>2018-01-16T13:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Security Header Not Detected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307590#M57930</link>
      <description>&lt;P&gt;The vunerability is highlighting a potential xss vector on the universal forwarders managment port.&lt;BR /&gt;
I am not sure which version of the UF you are running, if later than 6.6 you can add the missing headers as per: &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/412210/configuring-x-xss-protection-security-header.html"&gt;https://answers.splunk.com/answers/412210/configuring-x-xss-protection-security-header.html&lt;/A&gt;&lt;BR /&gt;
&lt;CODE&gt;replyHeader.X-Frame-Options = SAMEORIGIN&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Alternativly, you could chose to disable the MGT port on your UF entirely:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/233170/can-you-disable-the-management-port-8089-on-client.html"&gt;https://answers.splunk.com/answers/233170/can-you-disable-the-management-port-8089-on-client.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;p.s. I edited your question to include a translation and accidentally added the +25 bounty. I have asked for this to be removed.&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;A vunerability está destacando um potencial vetor xss na porta de gerenciamento de encaminhadores universais.&lt;BR /&gt;
Eu não tenho certeza sobre qual versão do UF você está executando, se, mais tarde do que 6.6, você pode adicionar os cabeçalhos ausentes conforme:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/412210/configuring-x-xss-protection-security-header.html"&gt;https://answers.splunk.com/answers/412210/configuring-x-xss-protection-security-header.html&lt;/A&gt;&lt;BR /&gt;
responseHeader.X-Frame-Options = SAMEORIGIN&lt;/P&gt;

&lt;P&gt;Alternativamente, você poderia optar por disable a porta MGT em seu UF inteiramente:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/233170/can-you-disable-the-management-port-8089-on-client.html"&gt;https://answers.splunk.com/answers/233170/can-you-disable-the-management-port-8089-on-client.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;p.s. Eu editei sua pergunta para incluir uma tradução e adicionei acidentalmente a generosidade +25. Pedi que isso fosse removido.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2018 15:50:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307590#M57930</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-16T15:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Security Header Not Detected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307591#M57931</link>
      <description>&lt;P&gt;@nickhillscpl, can you edit the question again and remove the bounty?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2018 14:21:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307591#M57931</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-02-05T14:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Security Header Not Detected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307592#M57932</link>
      <description>&lt;P&gt;Estava tendo o mesmo problema, ao atualizar no nosso master para 7.2 e os forwarders para o mais recente, nossos scans deixaram de apresentar o problema. Quais versões estão instaladas?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2018 16:07:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307592#M57932</guid>
      <dc:creator>felipesewaybric</dc:creator>
      <dc:date>2018-02-05T16:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Security Header Not Detected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307593#M57933</link>
      <description>&lt;P&gt;Interestingly, there doesn't seem to be a way to reverse it when editing the question. I'll bring this up to the developers of the site to look into this. I've granted @Hidebrando karma points as buffer if/when there is an accepted answer on this question. &lt;/P&gt;

&lt;P&gt;Thanks for pointing it out @nickhillscpl and @jkat54 for the suggestion &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 01:27:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307593#M57933</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2018-02-08T01:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Security Header Not Detected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307594#M57934</link>
      <description>&lt;P&gt;Did you find a solution for this challenge? &lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2020 15:16:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Security-Header-Not-Detected/m-p/307594#M57934</guid>
      <dc:creator>Tetonka</dc:creator>
      <dc:date>2020-05-08T15:16:25Z</dc:date>
    </item>
  </channel>
</rss>

