Skip to main content

Sec-helpers

Collection of dynamic security related helpers (DAST).

Sec-helpers is a bundle of useful tests and validators to ensure the security of a given domain.

Usage

  1. Install package pip install sec-helpers: https://pypi.org/project/sec-helpers
  2. Copy and change the following to run all the tests:
import sec_helpers

domain: str = 'vwt-digital.github.io' # {domain}.{tld}

sec_helpers.CorsPolicy(domain=domain)
sec_helpers.HighTls(domain=domain, slide=False) # Slide is False by default
sec_helpers.Hsts(domain=domain, age=10368000) # Age is 10368000 by default
sec_helpers.NoHttp(domain=domain)
sec_helpers.NoSsl(domain=domain)

Do you want all the sec-helpers ready in a container? Configure cloudbuilders-dast.

Exception

'NoSsl' requires and OpenSSL version with SSLv3 enabled. Check this Dockerfile and can be run using the following:
sec_helpers.NoSsl(domain={domain}.{tld}), but will result in exit code 0 when the wrong openssl version is present.

Helpers

NoHttp

Ensures domain redirects on http (and checks if https is active to not pass on incorrect domain)

Hsts

Ensures that the Strict-Transport-Security header on the domain is higher than 10368000

HighTls

Ensures that TLS versions on domain are inline with Mozilla's recommended configurations

NoSsl

Ensures that no SSL version is used.

CorsPolicy

Ensures that Allowed Origins are specified.

Examples

sec_helpers.HighTls({domain}.com)

-------
Protocol: TLSv1.3
Should be active: True
	Wrong configuration

-------
Protocol: TLSv1.2
Should be active: True
Connected with: TLSv1.2
Using cipher: ('{cipher_info}', 'TLSv1.2', 128)

-------
Protocol: TLSv1
Should be active: False

-------
Protocol: TLSv1.1
Should be active: False
Connected with: TLSv1.1
Using cipher: ('{cipher_info}', 'TLSv1.0', 128)
	Wrong configuration

Test on {domain}.com failed

TLSv1.3 is not active on domain: HighTls will fail. TLSv1.1 is active on domain: HighTls will fail.


sec_helpers.NoHttp({domain}.com)

Starting GET request to http://{domain}.com
GET request to http://{domain}.com returned status 302
Starting GET request to https://{domain}.com
GET request to https://{domain}.com returned status 200
Successful http status check: http is disabled or redirects to https

Http request returned 302 Found redirect. Https returned 200. NoHttp passed.


sec_helpers.Hsts({domain}.com)

Starting GET request to http://{domain}.com
Strict-Transport-Security header on https://{domain}.com returned max-age=31536000
Successful HSTS status check

Strict Transport Security header found, with max age 31536000. Hsts passed.


sec_helpers.CorsPolicy({domain}.com)

Failing policy test: No Allowed Origins Specified

No allowed origins specified. CorsPolicy failed.

Release files for sec-helpers 0.3.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sec-helpers 0.3.3
File Size Uploaded
sec-helpers-0.3.3.tar.gz 5.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sec-helpers 0.3.3
File Interpreter ABI Platform
sec_helpers-0.3.3-py3-none-any.whl Python 3 none any Details

Total release size: 24.6 kB

Release files / sec-helpers-0.3.3.tar.gz

Download URL sec-helpers-0.3.3.tar.gz
Size 5.2 kB
Tags Source
SHA-256 checksum
How to use checksums
9d35c99a8639193cfb188feab4adf4a7c4198643c5b5e503c7606b2fa16a47b2
BLAKE2b-256 checksum
How to use checksums
c74a5ccd13c897e3045820811c373399f1d2dd76a7f492cad98b4c3d67954fd5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/1.15.0 pkginfo/1.7.0 requests/2.25.1 setuptools/50.3.2 requests-toolbelt/0.9.1 tqdm/4.59.0 CPython/3.5.2

Release files / sec_helpers-0.3.3-py3-none-any.whl

Download URL sec_helpers-0.3.3-py3-none-any.whl
Size 19.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9c4798c4aae7501aeb2593d1493745e3a3ffed4b2ebf8f3ba60f25f975821991
BLAKE2b-256 checksum
How to use checksums
a89e5c3033b39e45d5078818e250af61508f8ed6e9aa4a74e7a4a8a2a3d1ce98
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/1.15.0 pkginfo/1.7.0 requests/2.25.1 setuptools/50.3.2 requests-toolbelt/0.9.1 tqdm/4.59.0 CPython/3.5.2

Release history Release notifications | RSS feed

This release

0.3.3 This release

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.1.0

2 release files

0.0.4

2 release files

0.0.3

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page