HTTP Headers

Back to Reports

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.

Statistic summary for Wednesday May 16th 2012. 21673 distinct hosts.
Header# of Hosts
Content-Type21673
Date21624
Server21365
Connection18567
Set-Cookie16338
X-Powered-By12684
Cache-Control10951
Content-Length8204
Expires7890
Last-Modified7381
Vary6862
Pragma6118
Accept-Ranges4701
ETag4640
X-Pingback3363
P3P1669
X-AspNet-Version1265
X-XSS-Protection859
X-Content-Type-Options846
Content-Location663
Link617
X-Cache412
Content-Language376
Via355
Age294
X-UA-Compatible242
X-Varnish185
X-Hacker162
MicrosoftOfficeWebServer155
Keep-Alive140
Status135
X-Pad131
WP-Super-Cache125
X-Runtime114
X-Tumblr-Usec95
X-Tumblr-User95
X-Cache-Lookup73
X-FRAME-OPTIONS70
X-Nananana69
X-Powered-By-Plesk64
MS-Author-Via62
X-AspNetMvc-Version62
X-Generator54
X-Powered-CMS52
X-Server49
X-Cnection45
X-Drupal-Cache41
X-Cacheable37
X-Host37
X-XRDS-Location36
X-Mod-Pagespeed32
X-Webserver29
X-PhApp29
X-XN-Trace-Token27
X-XN-XNHTML27
X-ServedBy26
X-INKT-SITE26
Content-Encoding26
X-INKT-URI26
X-Mobilized-By26
Composed-By25
Served-By25
X-Robots-Tag25
MicrosoftSharePointTeamServices23
Refresh20
Content-Script-Type17
Access-Control-Allow-Origin17
X-Rack-Cache16
X-Check15
X-Language15
X-Template15
X-Request-Id13
IISExport13
X-Cache-Hits12
X-CF-Powered-By11
X-BackEnd11
X-Served-By11
X-SharePointHealthScore11
SPRequestGuid11
X-Firenze-Processing-Times11
Content-Style-Type10
X-Whom10
X-Drectory-Script10
Imagetoolbar9
X-Umbraco-Version9
X-Outils-CS9
X-Cache-Server8
X-Alternate-Cache-Key8
PICS-Label8
X-Matrix-Server8
Xonnection7
X-Type7
TCN7
X-Cache-Group7
Page-Completion-Status7
X-Secret7
Cm-Server6
X-Server-Name6
Liferay-Portal6
X-FB-Debug6
X-Matrix-Proxy6
X-PHP-Engine5
X-Loop5
X-TN-ServedBy5
Real-Hostname5
X-Cache-Info5
X-Enhanced-By5
X-PWb-Node5
X-AH-Environment5
NS-RTIMER-COMPOSITE5
X-PosterousHostName5
X-GitSHA5
X-DDC-Arch-Trace5
X-RateLimit-Remaining5
X-RateLimit-Limit5
Generator5
COMMERCE-SERVER-SOFTWARE5
Powered-By-ChinaCache5
X-Amz-Id-24
Cartoon4
X-Haiku4
X-ELC-Checkpoint44
Access-Control-Allow-Headers4
B-Powered-By4
MIME-Version4
X-Px4
X-CJ-Soft4
X-GLaDOS4
IBM-Web2-Location4
X-Amz-Request-Id4
Location4
X-PF-Uncompressing4
X-Cache-Control-Orig3
X-Wily-Servlet3
Access-Control-Allow-Methods3
X-Bettercache-Proxy3
X-Wily-Info3
X-TNCMS-Memory-Usage3
X-Object-Id3
Wn-Vars3
X-Expires-Orig3
From3
Content-Disposition3
X-TNCMS-Render-Time3
X-Generated-By3
X-Object-Type3
SynthaSite-ID3
X-EdgeRouter3
Lsrequestid3
X-TNCMS-Version3
Thanks3
WN3
CP3
Railo-Version3
X-Content-Encoded-By3
X-Grid-Server3
Loadtime-Newsletter3
X-Page-Speed3
X-Cdn3
X-Yadis-Location3
X-TNCMS-Served-By3
X-Frontend2
X-MJ-Serve-Req-Time2
ServerName2
X-Cache-Control2
Page.Ly2
Progma2
X-SATserver2
X-MJ-Upstream-Addr2
ProxiaInstanceId2
X-Blog2
X-UPSTREAM2
X-PvInfo2
SN2
X-Cached-By2
X-GC-App2
X-Server-IP2
X-Varnish-IP2
Node2
X-Wix-Renderer-Server2
Powered-By2
CCEncrypt2
X-Software-Info2
X-GC-Read2
X-Varnish-Cache2
Content-Base2
Content2
X-Nginx-IP2
X-Firenze-Processing-Time2
Uniqueid2
X-DeliveryServer2
X-REDIRECTSERVER2
Surrogate-Control2
Warning2
Proxy-Connection2
Req-Timestamp2
X-GC-Write2
X-Seen-By2
Access-Control-Max-Age2
X-Vtex-Cache-Key2
X-MSG-062
D2
X-MSG-052
X-StoreSense2
X-MSG-042
X-Tiger-TTFB2
X-ProStores-StoreApiEntryPoint2
X-S2
Iinfo2
X-Vtex-Remote-Cache2
WS2
DeleGate-Ver2
X-MSG-032
X-MSG-022
X-MSG-012
X-MSG-002
X-DEBUG-X-Id2
No2
MASTERWEBLET2
X-Phpwcms-Page-Processed-In2
X-Phpwcms-Release2
X-Vary-Options2
X-Session-Reinit2
ServerID2
X-App-Server2
X-UD-Host2
X-Beatles2
X-Content-Digest2
WP-Cache2
X-Info2
X-Server-Id2
S2
X-UD-Target2
X-UD-Method2
Cache2
X-It-Host-Id1
X-SID1
MW-Server1
Www.Oyuncuadresi.Com1
X-LAvg1
X-Served-By-Node1
X-Varnish-Machine1
X-TTL1
X-Description1
X-Avvio-Cms-Cacheload1
X-COOKIEWAS31
X-Accelerated-By1
MWHOST1
X-ApacheHost1
X-Stopwatch1
X-CMS-Version1
X-Hostname1
Cache-Expires1
X-AspNetWebPages-Version1
Kp-EeAlive1
X-DIP1
PowerCDN1
X-PageId1
X-PoweredBy1
MyServer1
X-NOCOOKIEFOUND1
X-Server-By1
X-Zone1
X-Achmed-Status1
Robots1
X-Secoya-Server1
Varnish-Active1
X-Cache-Hit1
X-IsMobileHost1
X-IsFrontPageReq1
X-Cocoon-Version1
X-Powered-S1
X-Catalyst1
UniqueName1
X-Which-Box1
X-Country-Name1
X-Country1
X-Debug-Serve1
Last-Updated1
X-Version1
X-Pb-Mii1
X-DoRedirect1
Response-Server1
Response-File1
X-Bak1
X-Server-Admins1
X-Cache-Action1
ZoogleHost1
X-Url1
X-RE-Ref1
X-Set-Cookie1
X-VarnishNode1
Nodo1
X-Original-At1
X-DEBUG-Obj-Ttl1
Noahs-Classifieds1
A-Powered-By1
X-DOTLAN-License1
X-DOTLAN-Version1
GP-NGX1
X-WLD-LB1
X-Permitted-Cross-Domain-Policies1
QYSID1
X-WhitelistedCookie1
X-From1
X-Analytics-Terminal1
X-Node1
X-BServer1
Tempo1
Timing1
X-Content-Parsed-By1
X-PC3-Time1
X-PC3-Control1
X-Cache-Timing1
Servlet-Engine1
Il-Cl1
X-Amz-Meta-S3cmd-Attrs1
Server-Hostname1
X-Served2-By1
X-SUP-ID1
X-CMS-Powered-By1
X-From-Pagecache1
XServer1
SOSLoc1
X-DotDefender-Denied1
ScoreTracker1
X-Highwire-SessionId1
X-Libsyn-Host1
X-Varnish-Age1
X-Header-Set-Id1
X-Caching-Rule-Id1
X-ApacheServer1
Gzip1
Hacked1
ROCKandREVIEW.Com1
Lytee-CME-Version1
Lytee-Server1
X-Adobe-Content1
X-Highwire-RequestId1
With1
HOST-SERVICE1
X-Hrouter1
THIELI-VERSION1
X-Question1
X-Answer1
X-CAPP-PROFILING1
X-Generate1
X-Expires1
WCSITE1
Adepteo1
WSID1
X-I1
UNIQUE-ID1
X-Framework1
X-CacheServer1
X-Id1
X-Request-Duration1
X-Original-Request1
Title1
X-Confluence-Request-Time1
X-Duration1
Content-MD51
X-Server-Oad1
X-Handled-By1
Webserver1
X-Responding-Server1
Z-Powered-By1
Accept1
X-Time-Microsecs1
X-Empowered-By1
X3CMS-Release1
ZEONWEB-Cluster1
Beyond-Iis1
Page1
X-CacheHits1
X-VarnishServer1
X-Database-Slave-Connection1
X-AWS-Id1
If-Modified-Since1
CachedXSLT1
PROPSON-FARM1
X-FIRSTPAGE1
X-Passed-To-DLL1
X-End1
WP-AdvCache-MemCached1
Centent-Type1
X-Who-O1
X-Fueled-By1
Backend-INFRA.WAN1
X-20M-Cache1
X-PCS-TTL1
X-Ziosting-Rule1
X-Who-L1
User-Agent1
X-Beta1
X-Origin-Srv1
X-Who1
X-AP-Version1
X-AWCMS-Version1
X-Portal1
WP-KEY1
Filter-Revision1
X-Euro-ID1
X-Account-Management-Status1
Engine-Programming1
Web31
X-Passed-To1
Cluster1
Pagename1
Response1
X-Bstat1
X-Country-Code1
SVR1
X-PH-Magento-Cache1
WhoisCache1
X-SW1
Last-UpdatedL1
Cache-Ctrol1
X-Wf-Protocol-11
X-Varnish-Hits1
X-Back1
X-Aliases1
Wwwcr.Mossgreen.Com.Au1
X-Artvisual-Server1
Hola1
X-Purge-URL1
X-Ws1
X-Accelance-Front1
X-Purge-Host1
X-RCR1
Login-Required1
Hostedby1
X-Abuse1
P3P:CP1
VTag1
Cluster-Node1
X-Wf-1-Structure-11
X-Varnish-Backend1
X-Origin1
Www.Mossgreen.Com.Au1
NLCacheNote1
X-ODL-Server1
X-QueryRuntime1
X-Cached1
X-Ruby-Cluster-ID1
CDCHOST1
X-Actual-URL1
X-DmUser1
X-SSS-Version1
No-Cache1
LibAstro1
X-Cache21
X-Papaya-Gzip1
X-Invocation-Time1
Loadtime-SocialMedia1
X-PBY1
.Woff1
Loadtime-PropertyFeature1
Apache1
X-Debug1
Application-Version1
.Svg1
X-QueryCount1
X-Varnish-Hostname1
X-Real-Server1
X-Site1
X-Developer1
X-Realserver1
SL-NOREWRITE-REDIRECTS1
X-Papaya-Cache1
Vala1
Srv1
Cluster-Id1
X-CFRH1
X-MTX-DBCache[C-Pri-1926]1
X-UA-Comatible1
X-SRV1
Web-Hostname1
X-Wf-1-Plugin-11
X-Gentics1
X-FreeTag-Count1
ProxyTime1
X-App-Hosting1
Mossgreen.Com.Au1
X-Wm-11
X-LiteSpeed-Cache1
Server-N1
Origin1
X-CFRM21
ContentType1
X-Accel-Version1
Cache-Key1
X-MTX-DBCache[C-1899]1
X-Backend-Server1
01
X-Wf-1-1-1-11
X-Cache-NHIT1
ProxyServer1
X-N1
PFHOST1
X-Test1
Infra1
ASTrefflag1
X-Head1
X-ACMCache1
Req-Id1
X-Content-Security-Policy1
Hits1
Rating1
Content-Description1
X-Via1
X-MCB-Server1
Product-Version1
X-SmugMug-Hiring1
X-Oad-Xslt1
X-SmugMug-Values1
X-Source-Host1
X-Hosted-By1
Expire1
X-Powered-By-Home.Pl1
Charset1
X-Track1
X-Hit-Cache1
Provider1
X-Forwarded-For1
Host1
Content-Transfer-Encoding1
CommunityServer1
X-MS-InvokeApp1
Accept-Encoding1
X-Snapsis-PageBlaster1
Vserver1
X-Front1
X-User-Agent1
Accept-Charset1
X-Cache-Expires1
X-GAMECOUNTRY1
MST-Version1
X-Origin-Id1
X-UD-Loopcounter1
X-Eznode1
Db1
X-Nikon-Host1
X-Re-Srv1
X-Disclaimer1
X-Matchfwd-Misc1
X-Ants-Machine-Id1
X-Confirmit-ID1
X-USERCOUNTRY1
Reply-To1
Hishop1
X-VWS-Id1
X-Returned-From-DLL1
X-Returned-From1
X-Apache-IP1
X-Gateway1
WEBO1
Version1
X-20M-WebServer1
X-Filmed-By1
Proxy-Agent1
X-Web-Hosting-Service-Provider1
X-Matchfwd-GenTime1
X-Sportal-Origin1
Stylesheets1
X-PAGE1
Type1
X-Header1
X-Cache-Debug1
X-CF1
ERROR1
X-Sitemap-URL1
X-MTX-DBCache[C-1898]1
X-Stackable-Node1
X-Instance-Name1
Is-Cached1
AppTime1
X-FW1
X-PE-Server:1
Hostname1
ASTadv1
X-Powered-WP1
Server-Name1
X-Stat-Server1
X-ServerID1
Nectar1
Response-Type1
X-UD-REMOTE-ADDR1
X-Metrix-Cachesite1
X-Machine-ID1
X-RSS-CACHE-STATUS1
X-XTM-Node1
X-HN1
AppServer1
X-USERIP1
X-Amz-Cf-Id1
X-Oracle-DMS-ECID1
SmartCDS1