Test the public path, not just the server config
Load balancers, CDNs and reverse proxies can change redirects and response headers after the origin server configuration.
HTTP and HTTPS should be reviewed together
A secure HTTPS endpoint does not automatically mean the HTTP entry point behaves as expected.
HSTS is visible in the HTTPS response
The browser-facing header reveals whether the public service tells compatible browsers to prefer HTTPS in the future.
Online provides an outside-in check
Scantide Online can review HTTP/HTTPS reachability, TLS and security headers from the public side so teams can compare the delivered result with intended configuration.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web ExposureUse Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.
Current Scantide source: DNS, SPF and DMARC Security CheckerScantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.
Current Scantide source: Public Server Security AssessmentUse Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.
Current Scantide source: Website Security Header ScannerScantide Online reviews website security headers such as HSTS, CSP, X-Frame-Options and related browser controls in the context of the public site.
Current Scantide source: DNS, SPF and DMARC Security CheckerScantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.
Field experience from the archive
Historical source · JufCorp: Using HTTP redirects for mitigating vulnerability scans and bruteforce attacksAs a test, I changed all of the .php-files to simply redirect to https://www.google.com and then triggered a response by using an invalid username (I have mine set to immediately block if someone tries to use an invalid username) and, behold., it worked. Next time I tried to browse to /wp-admin I got redirected to Google for as long as the rule says so.
The redirect method will only protect your server on the http/s level. f you also have other services runnning such as FTP,RDP etc they won't be protected by a simple redirect on http/s only. There's other ways to accoomplish that and I'm happy to help you out. Just drop me an email or get in contact through the form to the right or below.
Historical source · JufCorp: Securing your servers, users and customers onlineAlso, you external DNS server needs to be secured! Have a word with your ISP or whoever is running the external DNS server and see what they've got in place.
Remember to check your mail queues on a regular basis If you're starting to have loads of undelivered mail to and from various domains you could actually have a DNS server that's under attack , not being able to service your Exchange server with required information .
Practical review checklist
- Use Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.
- Scantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.
- Use Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.
- Scantide Online reviews website security headers such as HSTS, CSP, X-Frame-Options and related browser controls in the context of the public site.
- Scantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.
- As a test, I changed all of the .php-files to simply redirect to https://www.google.com and then triggered a response by using an invalid username (I have mine set to immediately block if someone tries to use an invalid username) and, behold., it worked.
- Disbling compatibiliy check when opening 2003 .xls in @Office 2007 impossible.