HTTP Headers

Back to Reports

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.

Statistic summary for Wednesday May 16th 2012. 21688 distinct hosts.
Header# of Hosts
Content-Type21688
Date21645
Server21367
Connection18596
Set-Cookie16361
X-Powered-By12700
Cache-Control10945
Content-Length8237
Expires7897
Last-Modified7373
Vary6927
Pragma6089
Accept-Ranges4703
ETag4658
X-Pingback3337
P3P1675
X-AspNet-Version1249
X-XSS-Protection867
X-Content-Type-Options857
Content-Location680
Link611
X-Cache414
Content-Language374
Via360
Age302
X-UA-Compatible255
X-Varnish193
X-Hacker155
MicrosoftOfficeWebServer146
Keep-Alive138
Status136
WP-Super-Cache134
X-Pad124
X-Runtime118
X-Tumblr-User102
X-Tumblr-Usec102
X-Frame-Options81
X-Powered-By-Plesk67
X-Nananana65
X-Cache-Lookup64
X-AspNetMvc-Version55
MS-Author-Via55
X-Generator55
X-Server45
X-Cnection44
X-Host44
X-Drupal-Cache43
X-Powered-CMS42
X-XRDS-Location38
X-Cacheable37
X-PhApp30
X-Webserver30
X-INKT-URI28
X-XN-Trace-Token28
X-XN-XNHTML28
X-INKT-SITE28
X-Mobilized-By27
Composed-By25
X-Mod-Pagespeed24
X-ServedBy24
X-Robots-Tag24
Content-Script-Type22
Served-By21
REFRESH21
Content-Encoding20
MicrosoftSharePointTeamServices18
Access-Control-Allow-Origin18
X-CF-Powered-By17
X-Request-Id17
X-Rack-Cache16
X-Check14
X-Template14
X-Language14
X-Served-By13
X-Cache-Hits12
Content-Style-Type12
X-Outils-CS11
X-Backend11
X-Firenze-Processing-Times11
Pics-Label10
X-Generated-By10
IISExport10
X-Alternate-Cache-Key10
X-Cache-Server9
Imagetoolbar9
X-Matrix-Server9
X-SharePointHealthScore9
SPRequestGuid9
X-Umbraco-Version9
Page-Completion-Status9
X-Cache-Group8
X-Type8
Liferay-Portal8
X-Secret8
X-Drectory-Script8
X-FB-Debug7
Xonnection7
X-Whom6
X-Matrix-Proxy6
NS-RTIMER-COMPOSITE6
X-CJ-Soft6
X-DDC-Arch-Trace6
X-Enhanced-By5
X-PWb-Node5
X-Wily-Servlet5
MIME-Version5
X-Wily-Info5
Content-Disposition5
TCN5
X-Cdn5
Powered-By-ChinaCache5
X-RateLimit-Remaining5
X-GitSHA5
X-PosterousHostName5
X-CMS-Version5
X-RateLimit-Limit5
IBM-Web2-Location5
X-AH-Environment4
COMMERCE-SERVER-SOFTWARE4
Cm-Server4
Generator4
X-ELC-Checkpoint44
X-Server-Name4
X-PHP-Engine4
X-Px4
X-Grid-Server4
X-TN-ServedBy4
X-Loop4
X-Cache-Info4
Real-Hostname4
X-PvInfo4
Cartoon4
X-Content-Encoded-By4
Thanks3
X-UD-Host3
Accept-Encoding3
X-UD-Method3
X-Page-Speed3
X-UD-Target3
Location3
From3
Iinfo3
X-Amz-Id-23
X-Amz-Request-Id3
X-Software-Info3
X-Varnish-Cache3
X-PF-Uncompressing3
CP3
Loadtime-Newsletter3
X-Expires-Orig3
Railo-Version3
X-Cache-Control-Orig3
Access-Control-Allow-Headers3
X-ACMCache2
NLCacheNote2
Surrogate-Control2
X-Yadis-Location2
X-FORWARDED-FOR2
X-Firenze-Processing-Time2
X-Developer2
Host2
X-Wm-12
Provider2
Node2
ProxiaInstanceId2
X-Session-Reinit2
WP-Cache2
X-Head2
SN2
X-Blog2
X-Server-IP2
X-Cache-Control2
X-Varnish-IP2
X-SATserver2
X-Seen-By2
X-TNCMS-Render-Time2
X-GLaDOS2
D2
X-TNCMS-Served-By2
X-Haiku2
X-MCB-Server2
B-Powered-By2
X-TNCMS-Version2
X-Vary-Options2
S2
Cache2
X-Content-Digest2
X-UPSTREAM2
X-TNCMS-Memory-Usage2
CommunityServer2
CCEncrypt2
X-Wix-Renderer-Server2
X-StoreSense2
X-ProStores-StoreApiEntryPoint2
X-S2
Charset2
Lsrequestid2
Req-Timestamp2
Warning2
Uniqueid2
X-Nginx-IP2
Content-Base2
X-Bettercache-Proxy2
X-MSG-032
X-MSG-022
WCSITE2
X-Object-Type2
No2
X-Object-Id2
X-MSG-012
X-Amz-Cf-Id2
X-DEBUG-X-Id2
X-MSG-002
Page.Ly2
ServerID2
X-MSG-042
X-Vtex-Remote-Cache2
DeleGate-Ver2
X-MSG-052
Webserver2
X-MSG-062
X-ServerID2
X-Vtex-Cache-Key2
SynthaSite-ID2
X-EdgeRouter2
Access-Control-Allow-Methods2
X-Cached-By2
X-Hrouter1
X-App-Server1
X-Country-Name1
ZoogleHost1
X-DeliveryServer1
X-Url1
X-RE-Ref1
X-Content-Parsed-By1
X-Set-Cookie1
X-VarnishNode1
X-WhitelistedCookie1
X-Server-Admins1
Accept-Charset1
X-Bak1
MASTERWEBLET1
X-PC3-Control1
X-Hosted-By1
X-PC3-Time1
GP-NGX1
X-DOTLAN-Version1
X-DOTLAN-License1
A-Powered-By1
X-Beatles1
X-AspNetWebPages-Version1
Nodo1
X-Server-Id1
X-Original-At1
X-REDIRECTSERVER1
X-Header-Set-Id1
X-DEBUG-Obj-Ttl1
QYSID1
X-Permitted-Cross-Domain-Policies1
X-WLD-LB1
X-Cache-Timing1
UniqueName1
Hacked1
Gzip1
X-ApacheServer1
X-Caching-Rule-Id1
X-Varnish-Age1
X-Libsyn-Host1
Cache-Key1
X-Analytics-Terminal1
Lytee-CME-Version1
Lytee-Server1
ROCKandREVIEW.Com1
X-Achmed-Status1
X-DoRedirect1
X-Pb-Mii1
X-Version1
Last-Updated1
X-Debug-Serve1
X-Catalyst1
X-Country1
X-Which-Box1
X-Zone1
X-Generate1
X-Adobe-Content1
X-CAPP-PROFILING1
X-Answer1
X-Phpwcms-Release1
X-Phpwcms-Page-Processed-In1
X-Highwire-RequestId1
Response-Server1
X-Highwire-SessionId1
ScoreTracker1
Response-File1
Noahs-Classifieds1
X-Tiger-TTFB1
X-Cache-Action1
X-Cocoon-Version1
X-Powered-S1
X-Question1
THIELI-VERSION1
Progma1
X-Secoya-Server1
HOST-SERVICE1
Varnish-Active1
X-Cache-Hit1
X-IsMobileHost1
With1
X-IsFrontPageReq1
Robots1
Loadtime-SocialMedia1
WS1
X-Database-Slave-Connection1
X-Handled-By1
X-Server-Oad1
Content-MD51
Adepteo1
WSID1
X-I1
UNIQUE-ID1
X-Framework1
Wn-Vars1
X-CacheServer1
X-Id1
X-VarnishServer1
X-CacheHits1
Srv1
X-Expires1
X-Responding-Server1
X-Oad-Xslt1
Z-Powered-By1
Accept1
X-Time-Microsecs1
X-Empowered-By1
X3CMS-Release1
ZEONWEB-Cluster1
Beyond-Iis1
WN1
Page1
X-Request-Duration1
X-Original-Request1
Title1
X-Passed-To1
Cluster1
X-Beta1
User-Agent1
X-Who-L1
CachedXSLT1
PROPSON-FARM1
X-FIRSTPAGE1
X-Passed-To-DLL1
X-End1
WP-AdvCache-MemCached1
Centent-Type1
X-Who-O1
Web31
Engine-Programming1
X-Confluence-Request-Time1
X-Duration1
X-AWS-Id1
If-Modified-Since1
X-Origin-Srv1
X-Who1
X-AP-Version1
X-AWCMS-Version1
X-Portal1
WP-KEY1
Filter-Revision1
X-Euro-ID1
X-Account-Management-Status1
X-Fueled-By1
X-Bstat1
Hola1
X-Country-Code1
SVR1
Content1
X-PH-Magento-Cache1
WhoisCache1
X-SW1
Last-UpdatedL1
Cache-Ctrol1
X-Wf-Protocol-11
X-Varnish-Hits1
X-Back1
X-Aliases1
X-Purge-URL1
X-Ws1
X-Accelance-Front1
X-Purge-Host1
X-RCR1
Login-Required1
Hostedby1
X-Abuse1
P3P:CP1
VTag1
Cluster-Node1
X-Wf-1-Structure-11
X-Varnish-Backend1
X-Origin1
Www.Mossgreen.Com.Au1
Wwwcr.Mossgreen.Com.Au1
X-Artvisual-Server1
X-ODL-Server1
.Woff1
X-PBY1
X-QueryRuntime1
X-Cached1
X-Ruby-Cluster-ID1
CDCHOST1
X-Actual-URL1
X-DmUser1
X-SSS-Version1
No-Cache1
LibAstro1
X-Cache21
X-Papaya-Gzip1
Loadtime-PropertyFeature1
Vala1
Apache1
X-Debug1
Application-Version1
.Svg1
X-QueryCount1
X-Varnish-Hostname1
X-Info1
X-Real-Server1
X-Site1
X-Realserver1
SL-NOREWRITE-REDIRECTS1
Proxy-Connection1
X-Papaya-Cache1
X-Invocation-Time1
AppTime1
X-N1
PFHOST1
X-Test1
Infra1
ASTrefflag1
ContentType1
X-CFRM21
Origin1
X-MJ-Upstream-Addr1
X-MTX-DBCache[C-Pri-1926]1
X-UA-Comatible1
X-SRV1
Web-Hostname1
ProxyServer1
X-Cache-NHIT1
X-FW1
X-PE-Server:1
Hostname1
ASTadv1
SmartCDS1
X-Cache-Expires1
X-CFRH1
X-Accel-Version1
X-MJ-Serve-Req-Time1
X-MTX-DBCache[C-1899]1
X-Backend-Server1
01
X-Wf-1-1-1-11
X-Wf-1-Plugin-11
X-Gentics1
X-FreeTag-Count1
Expire1
Response1
Req-Id1
X-Content-Security-Policy1
Hits1
Rating1
Content-Description1
ServerName1
X-Via1
Product-Version1
X-SmugMug-Hiring1
X-Served2-By1
X-SmugMug-Values1
X-Powered-By-Home.Pl1
X-User-Agent1
ProxyTime1
X-App-Hosting1
Mossgreen.Com.Au1
X-LiteSpeed-Cache1
Server-N1
X-Track1
X-Hit-Cache1
Powered-By1
Content-Transfer-Encoding1
X-MS-InvokeApp1
X-Snapsis-PageBlaster1
Vserver1
X-Front1
X-Source-Host1
Backend-INFRA.WAN1
X-Matchfwd-GenTime1
X-Sportal-Origin1
Stylesheets1
X-PAGE1
X-Returned-From-DLL1
X-VWS-Id1
Hishop1
MST-Version1
X-Origin-Id1
X-UD-Loopcounter1
X-Eznode1
Db1
X-Nikon-Host1
X-Web-Hosting-Service-Provider1
Proxy-Agent1
X-20M-Cache1
X-PCS-TTL1
X-Ziosting-Rule1
Pagename1
Cluster-Id1
X-GAMECOUNTRY1
X-Returned-From1
X-Apache-IP1
X-Gateway1
WEBO1
Version1
X-20M-WebServer1
X-Filmed-By1
X-Re-Srv1
X-Disclaimer1
X-Matchfwd-Misc1
AppServer1
X-USERIP1
X-Oracle-DMS-ECID1
X-Stat-Server1
Server-Name1
X-Powered-WP1
X-Cache-Debug1
X-CF1
ERROR1
X-Sitemap-URL1
X-MTX-DBCache[C-1898]1
X-Stackable-Node1
X-Instance-Name1
X-HN1
X-XTM-Node1
X-Ants-Machine-Id1
X-Confirmit-ID1
X-USERCOUNTRY1
Reply-To1
Type1
X-Header1
Access-Control-Max-Age1
Nectar1
Response-Type1
X-UD-REMOTE-ADDR1
X-Metrix-Cachesite1
X-Machine-ID1
X-RSS-CACHE-STATUS1
Is-Cached1