https://sitecheck.sucuri.net/
Headers
https://securityheaders.com/
<VirtualHost *:80>
ProxyPreserveHost On
ProxyPass / http://127.0.0.1:9016/
ProxyPassReverse / http://127.0.0.1:9016/
ServerName aurora-web.drinux.com
ServerAlias aurora-web.drinux.com
Header always set x-Frame-Options "DENY"
Header always set X-Xss-Protection "1; mode=block"
Header always set X-Content-Type-Options "nosniff"
Header always set X-Content-Security-Policy "default-src 'self'; img-src 'self'; style-src 'self' 'unsafe-inline'; font-src 'self'; script-src 'self' 'unsafe-inline'; connect-src 'self';"
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Header always set X-Permitted-Cross-Domain-Policies "none"
Header always unset X-Powered-By
Header set Referrer-Policy "no-referrer"
Header set Content-Security-Policy "frame-ancestors 'self';"
Header set Permissions-Policy "accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()"
</VirtualHost>
Analisis de stress
https://a.blazemeter.com/
#seguridad