how to test HTTP strict transport security (hsts) in OWASP ZAP tool.
1,307 views
Skip to first unread message
Vemana
unread,
May 23, 2016, 3:23:40 PM5/23/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to OWASP ZAP Developer Group
Hi Friends,
Could you please let me know how to test the HTTP strict transport security (hsts) through OWASP ZAP tool ?
I did not see this Test under the passive scan rules.
Thanks in advance.
Vemana
thc...@gmail.com
unread,
May 23, 2016, 4:00:06 PM5/23/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to zaproxy...@googlegroups.com
Hi.
The scanner "Strict-Transport-Security Header Scanner" is (currently)
included in the add-on "Passive scanner rules (alpha)" [1], available in
the marketplace. [2]
(In the current version, 8, it's shown under a different name,
"Strict-Transport-Security Header Not Set".)