{"id":239451,"date":"2026-04-09T11:05:44","date_gmt":"2026-04-09T09:05:44","guid":{"rendered":"https:\/\/www.whiteshield.net\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/"},"modified":"2026-04-09T11:05:44","modified_gmt":"2026-04-09T09:05:44","slug":"webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat","status":"publish","type":"post","link":"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/","title":{"rendered":"Webalkalmaz\u00e1s biztons\u00e1g: a HTTP headerek hi\u00e1nya \u00fczleti kock\u00e1zat"},"content":{"rendered":"<h1><b>HTTP header \u00e9s webalkalmaz\u00e1s-biztons\u00e1g: az alul\u00e9rt\u00e9kelt v\u00e9delmi r\u00e9teg<\/b><\/h1>\n<p>A webalkalmaz\u00e1s-biztons\u00e1gr\u00f3l sz\u00f3l\u00f3 besz\u00e9lget\u00e9sek jellemz\u0151en a backend logik\u00e1ra, autentik\u00e1ci\u00f3ra, WAF-ra vagy \u00e9ppen a s\u00e9r\u00fcl\u00e9kenys\u00e9gvizsg\u00e1latokra f\u00f3kusz\u00e1lnak. Van azonban egy r\u00e9teg, amely annak ellen\u00e9re ritk\u00e1n ker\u00fcl reflektorf\u00e9nybe, hogy k\u00f6zvetlen hat\u00e1ssal van arra, hogy a b\u00f6ng\u00e9sz\u0151 mit kezd a szerver v\u00e1laszaival. Ez a r\u00e9teg a HTTP header konfigur\u00e1ci\u00f3.<\/p>\n<p>T\u00e9ny, hogy a megfelel\u0151en be\u00e1ll\u00edtott HTTP biztons\u00e1gi headerek nem l\u00e1tv\u00e1nyos kontrollok, hiszen nem jav\u00edtanak ki egy SQL injectiont, \u00e9s nem akad\u00e1lyoznak meg egyetlen logikai hib\u00e1t sem.\u00a0 Ugyanakkor minim\u00e1lis implement\u00e1ci\u00f3s k\u00f6lts\u00e9g mellett k\u00e9pesek jelent\u0151sen cs\u00f6kkenteni a kliensoldali t\u00e1mad\u00e1sok sikeress\u00e9g\u00e9t, ez\u00e9rt nem \u00e9rdemes figyelmen k\u00edv\u00fcl hagyni \u0151ket.<\/p>\n<h2><b>Mi az a HTTP header \u00e9s mi\u00e9rt sz\u00e1m\u00edt egy webalkalmaz\u00e1s eset\u00e9ben, hogy milyen?<\/b><\/h2>\n<p>A HTTP kommunik\u00e1ci\u00f3 sor\u00e1n a kliens (tipikusan egy b\u00f6ng\u00e9sz\u0151) \u00e9s a szerver struktur\u00e1lt \u00fczeneteket cser\u00e9l. Ezek k\u00e9t f\u0151 r\u00e9szb\u0151l \u00e1llnak: az egyiket az \u00fan. Headerek, vagyis metaadatok adj\u00e1k, a m\u00e1sikat pedig az \u00fan. body, vagyis a t\u00e9nyleges tartalom.<\/p>\n<p>A HTTP header kulcs-\u00e9rt\u00e9k p\u00e1rokb\u00f3l \u00e1ll, \u00e9s meghat\u00e1rozza, hogyan kell a v\u00e1laszt \u00e9rtelmezni vagy kezelni. Megmutatja p\u00e9ld\u00e1ul, hogy milyen t\u00edpus\u00fa a tartalom, meddig cache-elhet\u0151 \u00e9s milyen biztons\u00e1gi szab\u00e1lyokat kell alkalmazni a feldolgoz\u00e1s sor\u00e1n.<\/p>\n<p>A biztons\u00e1gi headerek enn\u00e9l egy l\u00e9p\u00e9ssel tov\u00e1bb mennek: konkr\u00e9t viselked\u00e9si szab\u00e1lyokat k\u00e9nyszer\u00edtenek ki a b\u00f6ng\u00e9sz\u0151n. Ez azonban nem jelenti, hogy a HTTP protokoll tov\u00e1bbi plusz v\u00e9delmi szoftverk\u00e9nt funkcion\u00e1l. Csak azt, hogy a protokoll nat\u00edv k\u00e9pess\u00e9geit tudatosan kihaszn\u00e1lva fokozhatjuk webalkalmaz\u00e1sunk biztons\u00e1goss\u00e1g\u00e1t.<\/p>\n<h3><b>Kiberv\u00e9delmi higi\u00e9nia: alacsony k\u00f6lts\u00e9g, magas hat\u00e1s<\/b><\/h3>\n<h3>A HTTP biztons\u00e1gi headerek tipikusan a kiberv\u00e9delmi higi\u00e9nia kateg\u00f3ri\u00e1j\u00e1ba tartoznak. Vagyis nem ig\u00e9nyelnek komplex fejleszt\u00e9st, a legt\u00f6bbsz\u00f6r infrastrukt\u00fara szinten konfigur\u00e1lhat\u00f3k, alkalmaz\u00e1sukkal m\u00e9gis m\u00e9rhet\u0151en cs\u00f6kkentik a t\u00e1mad\u00e1si fel\u00fcletet.<\/h3>\n<h3>A gyakorlatban szinte minden modern webszerver, reverse proxy vagy framework t\u00e1mogatja ezek be\u00e1ll\u00edt\u00e1s\u00e1t. Ha m\u00e9gsem szerepelnek a rendszerben, az ritk\u00e1n technol\u00f3giai korl\u00e1t, sokkal ink\u00e1bb priorit\u00e1si vagy tudatoss\u00e1gi k\u00e9rd\u00e9s.<\/h3>\n<h3><b>Milyen t\u00e1mad\u00e1sok ellen ny\u00fajtanak v\u00e9delmet a HTTP protokollok?<\/b><\/h3>\n<p>A helyesen konfigur\u00e1lt HTTP headerek nem egyetlen konkr\u00e9t t\u00e1mad\u00e1st \u00e1ll\u00edtanak meg, hanem t\u00f6bb t\u00e1mad\u00e1si vektor hat\u00e1s\u00e1t cs\u00f6kkentik. Ilyenek p\u00e9ld\u00e1ul a(z)<\/p>\n<ul>\n<li aria-level=\"1\">SSL stripping \u00e9s protokoll downgrade t\u00e1mad\u00e1sok (a titkos\u00edtott kapcsolat gyeng\u00edt\u00e9se);<\/li>\n<li aria-level=\"1\">cross-site scripting (XSS), amely val\u00f3j\u00e1ban valamely rosszindulat\u00fa script futtat\u00e1sa a b\u00f6ng\u00e9sz\u0151ben;<\/li>\n<li aria-level=\"1\"><a href=\"https:\/\/www.whiteshield.net\/hu\/clickjacking-amikor-egy-atlatszo-iframe-elteriti-a-kattintasodat\/\">clickjacking<\/a>, melynek sor\u00e1n a felhaszn\u00e1l\u00f3 manipul\u00e1l\u00e1s\u00e1ra ker\u00fcl sor rejtett UI elemekkel;<\/li>\n<li aria-level=\"1\">MIME sniffing alap\u00fa t\u00e1mad\u00e1sok (tartalomt\u00edpus f\u00e9lre\u00e9rtelmez\u00e9se);<\/li>\n<li aria-level=\"1\">adatsziv\u00e1rg\u00e1s referrer inform\u00e1ci\u00f3n kereszt\u00fcl;<\/li>\n<li aria-level=\"1\">nem indokolt b\u00f6ng\u00e9sz\u0151 API-hozz\u00e1f\u00e9r\u00e9sek (kamera, mikrofon stb.);<\/li>\n<li aria-level=\"1\">cross-origin adat-hozz\u00e1f\u00e9r\u00e9si probl\u00e9m\u00e1k.<\/li>\n<\/ul>\n<p>Fontos egy\u00e9rtelm\u0171s\u00edteni, hogy ezek a headerek nem patch-ek, mivel nem jav\u00edtanak ki semmilyen s\u00e9r\u00fcl\u00e9kenys\u00e9get. Ugyanakkor k\u00e9pesek jelent\u0151sen sz\u0171k\u00edteni az egyes s\u00e9r\u00fcl\u00e9kenys\u00e9gek esetleges kihaszn\u00e1l\u00e1si lehet\u0151s\u00e9geit.<\/p>\n<h2><b>A legfontosabb HTTP biztons\u00e1gi headerek<\/b><\/h2>\n<p><a href=\"https:\/\/www.whiteshield.net\/hu\/szolgaltatasaink\/penetracio-teszteles\/\">Penetr\u00e1ci\u00f3s tesztel\u00e9s<\/a> sor\u00e1n rendszeresen l\u00e1tjuk, hogy egy\u00e9bk\u00e9nt \u00e9rettnek gondolt webalkalmaz\u00e1s-k\u00f6rnyezetekben is hi\u00e1nyos vagy inkonzisztens a header-konfigur\u00e1ci\u00f3: m\u00e1s-m\u00e1s a stagingen \u00e9s a productionben, a reverse proxy \u00e9s az alkalmaz\u00e1sr\u00e9teg k\u00f6z\u00f6tt pedig teljesen sz\u00e9ttart\u00f3 be\u00e1ll\u00edt\u00e1sok m\u0171k\u00f6dnek.<\/p>\n<p>Ez az\u00e9rt probl\u00e9m\u00e1s, mert a b\u00f6ng\u00e9sz\u0151 nem kontextus alapj\u00e1n d\u00f6nt, hanem a kapott v\u00e1lasz szerint viselkedik. Azaz ha a policy nincs egy\u00e9rtelm\u0171en \u00e9s k\u00f6vetkezetesen defini\u00e1lva, akkor a kliensoldali t\u00e1mad\u00e1si fel\u00fclet l\u00e9nyeg\u00e9ben nyitva marad \u2013 f\u00fcggetlen\u00fcl att\u00f3l, mennyire er\u0151s a backend. Az al\u00e1bbiakban azokat a headereket vessz\u00fck v\u00e9gig, amelyek hi\u00e1nya vagy hib\u00e1s konfigur\u00e1ci\u00f3ja a leggyakrabban jelenik meg val\u00f3s t\u00e1mad\u00e1si forgat\u00f3k\u00f6nyvekben.<\/p>\n<h3><b>Strict-Transport-Security (HSTS)<\/b><\/h3>\n<p><b>P\u00e9lda: <\/b>Strict-Transport-Security: max-age=31536000; includeSubDomains; preload<\/p>\n<p>Azaz HSTS arra utas\u00edtja a b\u00f6ng\u00e9sz\u0151t, hogy kiz\u00e1r\u00f3lag HTTPS-en kommunik\u00e1ljon az adott domainnel.<\/p>\n<p><b>Mit jelent ez a gyakorlatban?<\/b><\/p>\n<p>A b\u00f6ng\u00e9sz\u0151 megjegyzi, hogy HTTP nem haszn\u00e1lhat\u00f3. Minden kapcsolat automatikusan HTTPS-re v\u00e1lt, a domain pedig ak\u00e1r a b\u00f6ng\u00e9sz\u0151k preload list\u00e1j\u00e1ba is beker\u00fclhet.<\/p>\n<p><b>Milyen probl\u00e9m\u00e1t kezel?<\/b><\/p>\n<p>Els\u0151sorban az SSL stripping t\u00e1mad\u00e1sok kezel\u00e9s\u00e9ben ny\u00fajt seg\u00edts\u00e9get. Ezek sor\u00e1n ugyanis a t\u00e1mad\u00f3 megpr\u00f3b\u00e1lja a felhaszn\u00e1l\u00f3t HTTP-re visszaterelni, hogy titkos\u00edtatlan forgalmat \u00e9rjen el. A HSTS ugyanakkor ezt egyszer\u0171en kiz\u00e1rja, mivel a a b\u00f6ng\u00e9sz\u0151 nem engedi a downgrade-et.<\/p>\n<h3><b>Content-Security-Policy (CSP)<\/b><\/h3>\n<p><b>P\u00e9lda: <\/b>Content-Security-Policy: default-src &#8216;self&#8217;; object-src &#8216;none&#8217;; frame-ancestors &#8216;none&#8217;;<\/p>\n<p>A CSP az egyik leger\u0151sebb kliensoldali kontroll, amely deklarat\u00edvan meghat\u00e1rozza, hogy a b\u00f6ng\u00e9sz\u0151 honnan t\u00f6lthet be er\u0151forr\u00e1sokat: JavaScript-b\u0151l, CSS-b\u0151l, k\u00e9pekb\u0151l,\u00a0 iframe-ekb\u0151l vagy API-h\u00edv\u00e1sokb\u00f3l.<\/p>\n<p><b>Mit csin\u00e1l?<\/b><\/p>\n<p>Az a HTTP csak saj\u00e1t domainr\u0151l enged bet\u00f6lt\u00e9st, tiltja a plugin alap\u00fa objektumokat \u00e9s megakad\u00e1lyozza az iframe-be \u00e1gyaz\u00e1st.<\/p>\n<p><b>Milyen probl\u00e9m\u00e1t kezel?<\/b><\/p>\n<p>Els\u0151sorban az XSS-t\u00e1mad\u00e1sok hat\u00e1s\u00e1t cs\u00f6kkenti. Fontos tudni, hogy nem felt\u00e9tlen\u00fcl akad\u00e1lyozza meg a s\u00e9r\u00fcl\u00e9kenys\u00e9get, viszont jelent\u0151sen korl\u00e1tozza a t\u00e1mad\u00f3 mozg\u00e1ster\u00e9t. (Jegyezz\u00fck meg: t\u00fal szigor\u00fa policy \u2192 t\u00f6r\u00f6tt frontend. T\u00fal laza policy \u2192 minim\u00e1lis v\u00e9delem.)<\/p>\n<h3><b>X-Content-Type-Options<\/b><\/h3>\n<p><b>P\u00e9lda: <\/b>X-Content-Type-Options: nosniff<\/p>\n<p>Ez a header megtiltja a b\u00f6ng\u00e9sz\u0151nek, hogy \u201ekital\u00e1lja\u201d a tartalom t\u00edpus\u00e1t.<\/p>\n<p><b>Mi\u00e9rt fontos?<\/b><\/p>\n<p>MIME sniffing eset\u00e9n a b\u00f6ng\u00e9sz\u0151 elt\u00e9rhet a deklar\u00e1lt Content-Type-t\u00f3l, \u00e9s potenci\u00e1lisan v\u00e9grehajthat\u00f3 k\u00f3dk\u00e9nt kezelhet egy f\u00e1jlt. A nosniff ezt a viselked\u00e9st tiltja.<\/p>\n<p><b>Jellemz\u0151je a <\/b>minim\u00e1lis implement\u00e1ci\u00f3, a gyakorlatilag mell\u00e9khat\u00e1smentes m\u0171k\u00f6d\u00e9s \u00e9s az, hogy ez a HTTP biztons\u00e1gi szempontb\u00f3l gyakorlatilag gyors gy\u0151zelem.<\/p>\n<h3><b>X-Frame-Options<\/b><\/h3>\n<p><b>P\u00e9lda: <\/b>X-Frame-Options: DENY vagy X-Frame-Options: SAMEORIGIN<\/p>\n<p>Ez a header szab\u00e1lyozza, hogy az oldal be\u00e1gyazhat\u00f3-e iframe-be.<\/p>\n<p><b>Milyen probl\u00e9m\u00e1t kezel?<\/b><\/p>\n<p>Seg\u00edti a clickjacking \u00e1ltali t\u00e1mad\u00e1sokkal szembeni v\u00e9dekez\u00e9st, melyek sor\u00e1n a t\u00e1mad\u00f3 egy legitim oldalt rejt el a saj\u00e1t UI-ja alatt, \u00e9s a felhaszn\u00e1l\u00f3t l\u00e1tsz\u00f3lag \u00e1rtalmatlan kattint\u00e1sra veszi r\u00e1, mik\u00f6zben val\u00f3j\u00e1ban p\u00e9ld\u00e1ul egy tranzakci\u00f3 j\u00f3v\u00e1hagy\u00e1s\u00e1ra.<\/p>\n<p><b>Eml\u00e9keztet\u0151:\u00a0 <\/b>A modern megk\u00f6zel\u00edt\u00e9s ink\u00e1bb a CSP frame-ancestors direkt\u00edv\u00e1ja, de az X-Frame-Options tov\u00e1bbra is egyszer\u0171 \u00e9s hat\u00e9kony baseline v\u00e9delem.<\/p>\n<h2><b>A HTTP biztons\u00e1gi headerek hi\u00e1nya \u00e9s hib\u00e1s konfigur\u00e1ci\u00f3ja rendszerszint\u0171 kock\u00e1zatot jelent<\/b><\/h2>\n<p>Pentesztek sor\u00e1n meglep\u0151en konzisztens mint\u00e1zat rajzol\u00f3dik ki: a HTTP biztons\u00e1gi headerek vagy teljesen hi\u00e1nyoznak, vagy \u00e9rdemi v\u00e9delem n\u00e9lk\u00fcl vannak jelen. Gyakori, hogy default konfigur\u00e1ci\u00f3k futnak \u00e9les k\u00f6rnyezetben, vagy a Content-Security-Policy form\u00e1lisan l\u00e9tezik, de val\u00f3j\u00e1ban mindent enged. \u00cdgy pedig ink\u00e1bb ny\u00fajt hamis biztons\u00e1g\u00e9rzetet, mint val\u00f3di kontrollt.<\/p>\n<p>A probl\u00e9ma nem az, hogy a HTTP protokollok be\u00e1ll\u00edt\u00e1sa komplex technikai l\u00e1t\u00e1sm\u00f3dot ig\u00e9nyel. Mivel a feladat ell\u00e1t\u00e1s\u00e1hoz nincs sz\u00fcks\u00e9g t\u00f6bb h\u00f3napos fejleszt\u00e9sre, vagy architektur\u00e1lis \u00fajratervez\u00e9sre, ez sem okozhat gondot.\u00a0<\/p>\n<p>Csakhogy m\u00edg a szervezet azon gondolkodik, ki\u00e9 a felel\u0151ss\u00e9g a konfigur\u00e1ci\u00f3\u00e9rt, mikor ker\u00fcl sor a be\u00e1ll\u00edt\u00e1sokra, \u00e9s egy\u00e1ltal\u00e1n priorit\u00e1s-e a HTTP-protokollok kialak\u00edt\u00e1sa, a s\u00e9r\u00fcl\u00e9kenys\u00e9gek tov\u00e1bbra is lehet\u0151s\u00e9get adnak az exploitokra.<\/p>\n<p>Ami igaz\u00e1n \u00e9rdekes az, hogy ezek a hi\u00e1nyoss\u00e1gok gyakran olyan rendszerekben jelennek meg, ahol egy\u00e9bk\u00e9nt komoly er\u0151forr\u00e1sokat ford\u00edtottak biztons\u00e1gra. Van WAF, MFA \u00e9s van audit, a b\u00f6ng\u00e9sz\u0151 viselked\u00e9se azonban m\u00e9gnincs kontroll alatt.<\/p>\n<h2><b>A HTTP header k\u00f6telez\u0151 alap<\/b><\/h2>\n<p>A HTTP biztons\u00e1gi headerek nem helyettes\u00edtik a biztons\u00e1gos fejleszt\u00e9st, a k\u00f3dmin\u0151s\u00e9get vagy a rendszeres s\u00e9r\u00fcl\u00e9kenys\u00e9gvizsg\u00e1latot, de egy olyan kontrollr\u00e9teget adnak a webalkalmaz\u00e1shoz, amely k\u00f6zvetlen\u00fcl befoly\u00e1solja a kliensoldali viselked\u00e9st. Megfelel\u0151 konfigur\u00e1ci\u00f3 mellett k\u00e9pesek cs\u00f6kkenteni a t\u00e1mad\u00e1si fel\u00fcletet, korl\u00e1tozni a sikeres exploitok hat\u00e1s\u00e1t, \u00e9s jelent\u0151sen megnehez\u00edteni a tipikus webes t\u00e1mad\u00e1si technik\u00e1k \u00e9rv\u00e9nyes\u00fcl\u00e9s\u00e9t.<\/p>\n<p>A bevezet\u00e9s\u00fck r\u00e1ad\u00e1sul ritk\u00e1n ig\u00e9nyel jelent\u0151s er\u0151forr\u00e1st: legt\u00f6bbsz\u00f6r infrastrukt\u00fara- vagy konfigur\u00e1ci\u00f3s szinten kezelhet\u0151k, \u00edgy gyorsan \u00e9s hat\u00e9konyan implement\u00e1lhat\u00f3k. \u00c9ppen ez\u00e9rt nem halad\u00f3 biztons\u00e1gi funkci\u00f3nak, sokkal ink\u00e1bb alapelv\u00e1r\u00e1snak tekinthet\u0151k.\u00a0<\/p>\n<p>Hi\u00e1nyuk persze nem felt\u00e9tlen\u00fcl jelent azonnali kompromitt\u00e1l\u00f3d\u00e1st, de indokolatlanul alacsonyan tartja a t\u00e1mad\u00e1si k\u00fcsz\u00f6b\u00f6t \u2013 \u00e9s ezt a t\u00e1mad\u00f3k pontosan tudj\u00e1k. Mert ha egy t\u00e1mad\u00f3 szem\u00e9vel n\u00e9zz\u00fck: mi\u00e9rt keresne komplex exploitot, ha a kliensoldali v\u00e9delem eleve nincs \u00e9rv\u00e9nyes\u00edtve?<\/p>\n<p><i>Ti mikor ellen\u0151rizt\u00e9tek utolj\u00e1ra webalkalmaz\u00e1sotok HTTP header konfigur\u00e1ci\u00f3j\u00e1t? Ha biztosak vagytok abban, hogy minden k\u00f6rnyezetben konzisztensen m\u0171k\u00f6dik, nincs tennival\u00f3tok. De ha seg\u00edts\u00e9gre van sz\u00fcks\u00e9getek, <\/i><a href=\"https:\/\/www.whiteshield.net\/hu\/kapcsolat\/\"><i>itt vagyunk.<\/i><\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>HTTP header \u00e9s webalkalmaz\u00e1s-biztons\u00e1g: az alul\u00e9rt\u00e9kelt v\u00e9delmi r\u00e9teg A webalkalmaz\u00e1s-biztons\u00e1gr\u00f3l sz\u00f3l\u00f3 besz\u00e9lget\u00e9sek jellemz\u0151en a backend logik\u00e1ra, autentik\u00e1ci\u00f3ra, WAF-ra vagy \u00e9ppen a s\u00e9r\u00fcl\u00e9kenys\u00e9gvizsg\u00e1latokra f\u00f3kusz\u00e1lnak. Van azonban egy r\u00e9teg, amely annak ellen\u00e9re ritk\u00e1n ker\u00fcl reflektorf\u00e9nybe, hogy k\u00f6zvetlen hat\u00e1ssal van arra, hogy a b\u00f6ng\u00e9sz\u0151 mit kezd a szerver v\u00e1laszaival. Ez a r\u00e9teg a HTTP header konfigur\u00e1ci\u00f3. T\u00e9ny, hogy [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":239449,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[33],"tags":[],"class_list":["post-239451","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-web-application-test-hu"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Webalkalmaz\u00e1s biztons\u00e1g: a HTTP headerek hi\u00e1nya \u00fczleti kock\u00e1zat - Whiteshield Ethical Hacking<\/title>\n<meta name=\"description\" content=\"Hi\u00e1nyz\u00f3 vagy hib\u00e1s HTTP headerek? Egy apr\u00f3 konfigur\u00e1ci\u00f3 komoly biztons\u00e1gi r\u00e9st nyithat. Megmutatjuk, hol buknak el a rendszerek \u00e9s mit \u00e9rdemes ellen\u0151rizni.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/\" \/>\n<meta property=\"og:locale\" content=\"hu_HU\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Webalkalmaz\u00e1s biztons\u00e1g: a HTTP headerek hi\u00e1nya \u00fczleti kock\u00e1zat - Whiteshield Ethical Hacking\" \/>\n<meta property=\"og:description\" content=\"Hi\u00e1nyz\u00f3 vagy hib\u00e1s HTTP headerek? Egy apr\u00f3 konfigur\u00e1ci\u00f3 komoly biztons\u00e1gi r\u00e9st nyithat. Megmutatjuk, hol buknak el a rendszerek \u00e9s mit \u00e9rdemes ellen\u0151rizni.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/\" \/>\n<meta property=\"og:site_name\" content=\"Whiteshield Ethical Hacking\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-09T09:05:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.whiteshield.net\/wp-content\/uploads\/2026\/04\/1775713804054.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1066\" \/>\n\t<meta property=\"og:image:height\" content=\"600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"whiteshield\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Szerz\u0151:\" \/>\n\t<meta name=\"twitter:data1\" content=\"whiteshield\" \/>\n\t<meta name=\"twitter:label2\" content=\"Becs\u00fclt olvas\u00e1si id\u0151\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 perc\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\\\/\"},\"author\":{\"name\":\"whiteshield\",\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/#\\\/schema\\\/person\\\/46c6efc500d7d7a6469670b2b6f25343\"},\"headline\":\"Webalkalmaz\u00e1s biztons\u00e1g: a HTTP headerek hi\u00e1nya \u00fczleti kock\u00e1zat\",\"datePublished\":\"2026-04-09T09:05:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\\\/\"},\"wordCount\":1721,\"image\":{\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.whiteshield.net\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/1775713804054.png\",\"articleSection\":[\"web application test\"],\"inLanguage\":\"hu\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\\\/\",\"url\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\\\/\",\"name\":\"Webalkalmaz\u00e1s biztons\u00e1g: a HTTP headerek hi\u00e1nya \u00fczleti kock\u00e1zat - Whiteshield Ethical Hacking\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.whiteshield.net\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/1775713804054.png\",\"datePublished\":\"2026-04-09T09:05:44+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/#\\\/schema\\\/person\\\/46c6efc500d7d7a6469670b2b6f25343\"},\"description\":\"Hi\u00e1nyz\u00f3 vagy hib\u00e1s HTTP headerek? Egy apr\u00f3 konfigur\u00e1ci\u00f3 komoly biztons\u00e1gi r\u00e9st nyithat. Megmutatjuk, hol buknak el a rendszerek \u00e9s mit \u00e9rdemes ellen\u0151rizni.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\\\/#breadcrumb\"},\"inLanguage\":\"hu\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"hu\",\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.whiteshield.net\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/1775713804054.png\",\"contentUrl\":\"https:\\\/\\\/www.whiteshield.net\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/1775713804054.png\",\"width\":1066,\"height\":600},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Webalkalmaz\u00e1s biztons\u00e1g: a HTTP headerek hi\u00e1nya \u00fczleti kock\u00e1zat\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/#website\",\"url\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/\",\"name\":\"Whiteshield Ethical Hacking\",\"description\":\"Biztons\u00e1gi Szak\u00e9rt\u0151k\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"hu\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/#\\\/schema\\\/person\\\/46c6efc500d7d7a6469670b2b6f25343\",\"name\":\"whiteshield\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"hu\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f935080e659dbad6cbf2290fa03176decaf657bbf1d7fbcd776d4adbdac6c827?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f935080e659dbad6cbf2290fa03176decaf657bbf1d7fbcd776d4adbdac6c827?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f935080e659dbad6cbf2290fa03176decaf657bbf1d7fbcd776d4adbdac6c827?s=96&d=mm&r=g\",\"caption\":\"whiteshield\"},\"url\":\"https:\\\/\\\/www.whiteshield.net\\\/hu\\\/author\\\/wsadmin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Webalkalmaz\u00e1s biztons\u00e1g: a HTTP headerek hi\u00e1nya \u00fczleti kock\u00e1zat - Whiteshield Ethical Hacking","description":"Hi\u00e1nyz\u00f3 vagy hib\u00e1s HTTP headerek? Egy apr\u00f3 konfigur\u00e1ci\u00f3 komoly biztons\u00e1gi r\u00e9st nyithat. Megmutatjuk, hol buknak el a rendszerek \u00e9s mit \u00e9rdemes ellen\u0151rizni.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/","og_locale":"hu_HU","og_type":"article","og_title":"Webalkalmaz\u00e1s biztons\u00e1g: a HTTP headerek hi\u00e1nya \u00fczleti kock\u00e1zat - Whiteshield Ethical Hacking","og_description":"Hi\u00e1nyz\u00f3 vagy hib\u00e1s HTTP headerek? Egy apr\u00f3 konfigur\u00e1ci\u00f3 komoly biztons\u00e1gi r\u00e9st nyithat. Megmutatjuk, hol buknak el a rendszerek \u00e9s mit \u00e9rdemes ellen\u0151rizni.","og_url":"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/","og_site_name":"Whiteshield Ethical Hacking","article_published_time":"2026-04-09T09:05:44+00:00","og_image":[{"width":1066,"height":600,"url":"https:\/\/www.whiteshield.net\/wp-content\/uploads\/2026\/04\/1775713804054.png","type":"image\/png"}],"author":"whiteshield","twitter_card":"summary_large_image","twitter_misc":{"Szerz\u0151:":"whiteshield","Becs\u00fclt olvas\u00e1si id\u0151":"9 perc"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/#article","isPartOf":{"@id":"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/"},"author":{"name":"whiteshield","@id":"https:\/\/www.whiteshield.net\/hu\/#\/schema\/person\/46c6efc500d7d7a6469670b2b6f25343"},"headline":"Webalkalmaz\u00e1s biztons\u00e1g: a HTTP headerek hi\u00e1nya \u00fczleti kock\u00e1zat","datePublished":"2026-04-09T09:05:44+00:00","mainEntityOfPage":{"@id":"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/"},"wordCount":1721,"image":{"@id":"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/#primaryimage"},"thumbnailUrl":"https:\/\/www.whiteshield.net\/wp-content\/uploads\/2026\/04\/1775713804054.png","articleSection":["web application test"],"inLanguage":"hu"},{"@type":"WebPage","@id":"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/","url":"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/","name":"Webalkalmaz\u00e1s biztons\u00e1g: a HTTP headerek hi\u00e1nya \u00fczleti kock\u00e1zat - Whiteshield Ethical Hacking","isPartOf":{"@id":"https:\/\/www.whiteshield.net\/hu\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/#primaryimage"},"image":{"@id":"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/#primaryimage"},"thumbnailUrl":"https:\/\/www.whiteshield.net\/wp-content\/uploads\/2026\/04\/1775713804054.png","datePublished":"2026-04-09T09:05:44+00:00","author":{"@id":"https:\/\/www.whiteshield.net\/hu\/#\/schema\/person\/46c6efc500d7d7a6469670b2b6f25343"},"description":"Hi\u00e1nyz\u00f3 vagy hib\u00e1s HTTP headerek? Egy apr\u00f3 konfigur\u00e1ci\u00f3 komoly biztons\u00e1gi r\u00e9st nyithat. Megmutatjuk, hol buknak el a rendszerek \u00e9s mit \u00e9rdemes ellen\u0151rizni.","breadcrumb":{"@id":"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/#breadcrumb"},"inLanguage":"hu","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/"]}]},{"@type":"ImageObject","inLanguage":"hu","@id":"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/#primaryimage","url":"https:\/\/www.whiteshield.net\/wp-content\/uploads\/2026\/04\/1775713804054.png","contentUrl":"https:\/\/www.whiteshield.net\/wp-content\/uploads\/2026\/04\/1775713804054.png","width":1066,"height":600},{"@type":"BreadcrumbList","@id":"https:\/\/www.whiteshield.net\/hu\/webalkalmazas-biztonsag-a-http-headerek-hianya-uzleti-kockazat\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.whiteshield.net\/hu\/"},{"@type":"ListItem","position":2,"name":"Webalkalmaz\u00e1s biztons\u00e1g: a HTTP headerek hi\u00e1nya \u00fczleti kock\u00e1zat"}]},{"@type":"WebSite","@id":"https:\/\/www.whiteshield.net\/hu\/#website","url":"https:\/\/www.whiteshield.net\/hu\/","name":"Whiteshield Ethical Hacking","description":"Biztons\u00e1gi Szak\u00e9rt\u0151k","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.whiteshield.net\/hu\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"hu"},{"@type":"Person","@id":"https:\/\/www.whiteshield.net\/hu\/#\/schema\/person\/46c6efc500d7d7a6469670b2b6f25343","name":"whiteshield","image":{"@type":"ImageObject","inLanguage":"hu","@id":"https:\/\/secure.gravatar.com\/avatar\/f935080e659dbad6cbf2290fa03176decaf657bbf1d7fbcd776d4adbdac6c827?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f935080e659dbad6cbf2290fa03176decaf657bbf1d7fbcd776d4adbdac6c827?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f935080e659dbad6cbf2290fa03176decaf657bbf1d7fbcd776d4adbdac6c827?s=96&d=mm&r=g","caption":"whiteshield"},"url":"https:\/\/www.whiteshield.net\/hu\/author\/wsadmin\/"}]}},"_links":{"self":[{"href":"https:\/\/www.whiteshield.net\/hu\/wp-json\/wp\/v2\/posts\/239451","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whiteshield.net\/hu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whiteshield.net\/hu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whiteshield.net\/hu\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whiteshield.net\/hu\/wp-json\/wp\/v2\/comments?post=239451"}],"version-history":[{"count":0,"href":"https:\/\/www.whiteshield.net\/hu\/wp-json\/wp\/v2\/posts\/239451\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.whiteshield.net\/hu\/wp-json\/wp\/v2\/media\/239449"}],"wp:attachment":[{"href":"https:\/\/www.whiteshield.net\/hu\/wp-json\/wp\/v2\/media?parent=239451"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whiteshield.net\/hu\/wp-json\/wp\/v2\/categories?post=239451"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whiteshield.net\/hu\/wp-json\/wp\/v2\/tags?post=239451"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}