TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Analyzing the Top 10,000 Websites' HTTP Headers

79 点作者 fmavituna超过 13 年前

5 条评论

marcinw超过 13 年前
Wow, 61% of websites that responded with an Access-Control-Allow-Origin header had a value set to "*". This allows for the website to be access in a cross-domain manner (think XSS, global wild cards in crossdomain.xml, etc).<p>I'm worried to think how site operators will adopt CSP (Content Security Policy) once it starts to gain traction.
评论 #2970121 未加载
CWIZO超过 13 年前
It's down for me. Cached version: <a href="http://webcache.googleusercontent.com/search?q=cache:BVs3oHYHqDcJ:www.shodanhq.com/research/infodisc/report+http://www.shodanhq.com/research/infodisc/report&#38;cd=1&#38;hl=en&#38;ct=clnk" rel="nofollow">http://webcache.googleusercontent.com/search?q=cache:BVs3oHY...</a>
Sukotto超过 13 年前
What does "grabbing the <i>banners</i> of those websites" mean?<p>What would I type into wget or curl to download the "banner" of a site?
评论 #2969598 未加载
ck2超过 13 年前
Correct me if I am wrong but any of those extra headers except "Strict-Transport-Security" actually REDUCE security.<p>By default the browser will be in it's more secure state and those headers actually drop the security to allow cross communication with (specific) other websites.
评论 #2970103 未加载
GoGlobal超过 13 年前
Page is down...
评论 #2970926 未加载