my.policy.ae | Report Generated:
4
Require immediate attention
6
Should be addressed ASAP
3
Address in next update
2
Consider for future
The application lacks essential security headers, exposing users to cross-site scripting (XSS), clickjacking, and other client-side attacks. Nikto scan confirmed missing headers.
# HTTP Header Analysis curl -I https://my.policy.ae HTTP/1.1 200 OK Content-Type: text/html Server: Microsoft-IIS/10.0 # Missing Headers: # X-Frame-Options (Nikto finding) # Strict-Transport-Security (Nikto finding) # X-Content-Type-Options (Nikto finding) # Content-Security-Policy # Referrer-Policy
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-ancestors 'none';";
# Fix for Nikto findings add_header X-Frame-Options "DENY"; add_header X-Content-Type-Options "nosniff"; add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"; add_header Referrer-Policy "strict-origin-when-cross-origin";
web.config under <system.webServer>curl -I https://my.policy.aeNikto scan discovered multiple potentially sensitive backup files accessible on the server (.pem, .jks, .war, .cer, .tgz, etc.). These files may contain sensitive information.
# Sample of exposed files found by Nikto /my.policy.pem /ae.jks /mypolicy.war /backup.tgz /database.tar # Test access to backup files curl -k https://my.policy.ae/backup.tgz --output backup.tgz file backup.tgz
# On server: rm /path/to/backup.tgz rm /path/to/database.tar rm /path/to/*.pem rm /path/to/*.jks
# .htaccess for Apache
<FilesMatch "\.(pem|jks|cer|war|tar|tgz|bak|old)$">
Deny from all
</FilesMatch>
# web.config for IIS
<security>
<requestFiltering>
<fileExtensions>
<add fileExtension=".pem" allowed="false" />
<add fileExtension=".jks" allowed="false" />
<add fileExtension=".war" allowed="false" />
</fileExtensions>
</requestFiltering>
</security>
Nikto scan found /test.php exposing PHP version and system information via
phpinfo(). This gives attackers valuable system information.
# Access test.php directly curl -k https://my.policy.ae/test.php # Sample output contains: PHP Version 8.2.22 System Information Loaded Configuration File Directive Local Value Master Value ... # This exposes too much information
rm /path/to/test.php
# In php.ini disable_functions = phpinfo
curl -k https://my.policy.ae/test.php # Should return 404
Nikto scan detected that the HTTP TRACE method is enabled. This could allow Cross-Site Tracing (XST) attacks.
# Test TRACE method curl -X TRACE https://my.policy.ae -v # Sample vulnerable response: < HTTP/1.1 200 OK < Content-Type: message/http < Content-Length: 39 < TRACE / HTTP/1.1 Host: my.policy.ae User-Agent: curl/7.68.0
# Apache
RewriteEngine On
RewriteCond %{REQUEST_METHOD} ^TRACE
RewriteRule .* - [F]
# Nginx
if ($request_method ~ ^(TRACE|TRACK)$ ) {
return 405;
}
# IIS (web.config)
<system.webServer>
<security>
<requestFiltering>
<verbs>
<add verb="TRACE" allowed="false" />
</verbs>
</requestFiltering>
</security>
</system.webServer>
curl -X TRACE https://my.policy.ae -v # Should return 405 Method Not Allowed
Host: my.policy.ae
IP: 20.174.53.113 (Azure)
ASN: AS8075 (Microsoft)
DNS Server: ns1-03.azure-dns.com
TTL: 3600
Created: 2023-05-13
Updated: 2025-05-13
Server: Microsoft-IIS/10.0 OS: Windows Server (Azure) PHP Version: 8.2.22 (from phpinfo) TLS: TLS_AES_256_GCM_SHA384 Certificate: Let's Encrypt R11
Total 151 potentially sensitive files identified by Nikto
The network firewall allows unnecessary ports and services, increasing attack surface.
# Azure Network Security Group priority: 100, source: *, dest: *, port: 53, protocol: UDP, action: Allow priority: 110, source: *, dest: *, port: 53, protocol: TCP, action: Deny priority: 120, source: *, dest: *, port: 3389, action: Deny (RDP) priority: 130, source: *, dest: *, port: 22, action: Deny (SSH) priority: 140, source: *, dest: *, port: 80, action: Allow priority: 150, source: *, dest: *, port: 443, action: Allow priority: 160, source: *, dest: *, port: *, action: Deny
Red indicators show firewall and web server vulnerabilities
HTTP/1.1 200 OK Content-Type: text/html Last-Modified: Tue, 13 May 2025 08:45:31 GMT Accept-Ranges: bytes ETag: "8073262e3c3db1:0" Vary: Accept-Encoding Server: Microsoft-IIS/10.0 Date: Tue, 13 May 2025 16:43:32 GMT Content-Length: 44203
| Priority | Vulnerability | Timeline | Owner | Status |
|---|---|---|---|---|
| Critical | Security Headers | Immediate (24h) | DevOps Team | Pending |
| Critical | Backup Files Exposure | 1-3 Days | Security Team | In Progress |
| High | PHP Info Exposure | Immediate (24h) | Dev Team | Fixed |
| Medium | TRACE Method Enabled | 1-2 Weeks | Infra Team | Pending |
# /etc/nginx/nginx.conf or site configuration
server {
# Security Headers
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-ancestors 'none';";
add_header X-Frame-Options "DENY";
add_header X-Content-Type-Options "nosniff";
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
add_header Referrer-Policy "strict-origin-when-cross-origin";
# Additional security
server_tokens off;
add_header X-Permitted-Cross-Domain-Policies "none";
}
# .htaccess or httpd.conf Header always set Content-Security-Policy "default-src 'self'" Header always set X-Frame-Options "DENY" Header always set X-Content-Type-Options "nosniff" Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" Header always set Referrer-Policy "strict-origin-when-cross-origin" # Disable server tokens ServerTokens Prod ServerSignature Off
web.config:
<system.webServer>
<httpProtocol>
<customHeaders>
<add name="Content-Security-Policy" value="default-src 'self'" />
<add name="X-Frame-Options" value="DENY" />
<add name="X-Content-Type-Options" value="nosniff" />
<add name="Strict-Transport-Security" value="max-age=63072000; includeSubDomains; preload" />
<add name="Referrer-Policy" value="strict-origin-when-cross-origin" />
</customHeaders>
</httpProtocol>
<security>
<requestFiltering removeServerHeader="true" />
</security>
</system.webServer>
# On server: find /var/www/html -name "*.bak" -o -name "*.old" -o -name "*.tar" -o -name "*.tgz" -delete
# .htaccess for Apache
<FilesMatch "\.(pem|jks|cer|war|tar|tgz|bak|old|sql|ini)$">
Deny from all
</FilesMatch>
rm /path/to/test.php
# In php.ini disable_functions = exec,passthru,shell_exec,system,proc_open,popen,curl_exec,curl_multi_exec,parse_ini_file,show_source
# In php.ini open_basedir = /var/www/html/
Security Consultant | CEH (CERTIFIED ETHICAL HACKER)
Report ID: SEC-2025-013
Assessment Date: May 13-15, 2025
Methodology: OWASP Web Testing
Tools Used: Burp Suite, Nmap, Nikto, Nuclei
Test Duration: 12 hours 45 minutes
Vulnerabilities Found: 15
Contact: cyberexploithack@gmail.com
Follow Up: Retesting available upon request