1

After scaning web page with Nikto I have results that is "The Content-Encoding header is set to "deflate" this may mean that the server is vulnerable to the BREACH attack."

How to verify if that result isn't false positive? In proxy I don't see any Content-Encoding: deflate header.

Is it a good solution to always disable deflate encoding?

user187205
  • 1,323
  • 3
  • 21
  • 35

0 Answers0