update
|
|
@ -0,0 +1,52 @@
|
||||||
|
# ── HTTPS Redirect ──────────────────────────────────────────────────────────
|
||||||
|
RewriteEngine On
|
||||||
|
RewriteCond %{HTTPS} off
|
||||||
|
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
|
||||||
|
|
||||||
|
# ── Security Headers ─────────────────────────────────────────────────────────
|
||||||
|
# HSTS: tell browsers to always use HTTPS (1 year). Add "; preload" and submit
|
||||||
|
# to https://hstspreload.org once you're confident HTTPS is permanent.
|
||||||
|
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
|
||||||
|
|
||||||
|
# Prevent MIME-type sniffing
|
||||||
|
Header always set X-Content-Type-Options "nosniff"
|
||||||
|
|
||||||
|
# Block this site from being embedded in iframes
|
||||||
|
Header always set X-Frame-Options "DENY"
|
||||||
|
|
||||||
|
# Control how much referrer info is sent to external sites
|
||||||
|
Header always set Referrer-Policy "strict-origin-when-cross-origin"
|
||||||
|
|
||||||
|
# Disable browser features not used by this site
|
||||||
|
Header always set Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=()"
|
||||||
|
|
||||||
|
# Prevent cross-origin window attacks
|
||||||
|
Header always set Cross-Origin-Opener-Policy "same-origin"
|
||||||
|
|
||||||
|
# Restrict cross-origin resource loading
|
||||||
|
Header always set Cross-Origin-Resource-Policy "same-origin"
|
||||||
|
|
||||||
|
# Content Security Policy
|
||||||
|
# - script/style 'unsafe-inline' required for inline blocks in both pages
|
||||||
|
# - fonts.googleapis.com for Google Fonts CSS; fonts.gstatic.com for font files
|
||||||
|
# - ki5bhv.com for the profile photo
|
||||||
|
Header always set Content-Security-Policy "default-src 'none'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' https://ki5bhv.com data:; connect-src 'none'; frame-src 'none'; object-src 'none'; base-uri 'self'; form-action 'none'; upgrade-insecure-requests"
|
||||||
|
|
||||||
|
# ── Strip Server Info ─────────────────────────────────────────────────────────
|
||||||
|
Header always unset X-Powered-By
|
||||||
|
Header always unset Server
|
||||||
|
|
||||||
|
# ── security.txt: also serve from /.well-known/ per RFC 9116 ─────────────────
|
||||||
|
RedirectMatch 301 ^/.well-known/security.txt$ /security.txt
|
||||||
|
|
||||||
|
# ── Sitemap ───────────────────────────────────────────────────────────────────
|
||||||
|
# Declared here so crawlers that read robots.txt can find it
|
||||||
|
# (also declared in robots.txt if you add one)
|
||||||
|
|
||||||
|
# ── Disable directory listing ─────────────────────────────────────────────────
|
||||||
|
Options -Indexes
|
||||||
|
|
||||||
|
# ── Protect dotfiles ──────────────────────────────────────────────────────────
|
||||||
|
<FilesMatch "^\.">
|
||||||
|
Require all denied
|
||||||
|
</FilesMatch>
|
||||||
|
|
@ -0,0 +1,3 @@
|
||||||
|
{
|
||||||
|
"CurrentProjectSetting": null
|
||||||
|
}
|
||||||
|
Before Width: | Height: | Size: 3.1 KiB After Width: | Height: | Size: 3.1 KiB |
|
Before Width: | Height: | Size: 473 B After Width: | Height: | Size: 473 B |
|
Before Width: | Height: | Size: 826 B After Width: | Height: | Size: 826 B |
|
Before Width: | Height: | Size: 4.3 KiB After Width: | Height: | Size: 4.3 KiB |
|
|
@ -0,0 +1,29 @@
|
||||||
|
-----BEGIN PGP SIGNED MESSAGE-----
|
||||||
|
Hash: SHA256
|
||||||
|
|
||||||
|
#Generated by https://github.com/gitaware/securitytxtgenerator
|
||||||
|
|
||||||
|
# If you would like to report a security issue, please contact us at:
|
||||||
|
Contact: justin@k5bss.com
|
||||||
|
Expires: 2027-04-20T01:14:00Z
|
||||||
|
Preferred-Languages: en
|
||||||
|
Canonical: https://k5bss.com/security.txt
|
||||||
|
Encryption: https://k5bss.com/pgp-key.asc
|
||||||
|
|
||||||
|
-----BEGIN PGP SIGNATURE-----
|
||||||
|
|
||||||
|
wsFzBAEBCAAnBYJp5onuCZB2Xap8YgdeNhYhBK0QLg9LuG9EuLvfkHZdqnxi
|
||||||
|
B142AAAlIw//Y//VEh32G+tXnamBIuYq4W+vdBlwZuKGeW/IwObedw89bGwo
|
||||||
|
/xSPGWUh0mPKKLof1MtLWNObUUCBscRZiLArExFzw/OZy2J3VuAH5qBrl2am
|
||||||
|
D8dnl/6CbqdrpEI3cinrzgDoa1Z4F15wF5lLNlvYHCGkXFIpNFsd8H6P9/UZ
|
||||||
|
v0jM6l93wDWbEZR1rHIxvtoUQd8gfPwksGa+osj6QkpP7XBRRly6nAihk8u7
|
||||||
|
r+aZ1Sh+YfWiVH966mxmV0x9N2ihYgYmwPMPUNCSRgpDZgM3EEKZWHryuPu2
|
||||||
|
Sp5q3bxa6BahAEXFhYaJKinkL5O95vaxiJcsaqPRhlR2xHXLoQj9Ot5v5E9c
|
||||||
|
uUc2P0v4M/VLFFTWwnu+3z72V/sj32biRJ70hvH/bb58oOm7YAcOCERyFsY+
|
||||||
|
4Drcnt2Am7QDEojhdg3GYf9pJs0tsyvmTZsmpYN8pv3lfzUzEW2YUOdWjMOf
|
||||||
|
nLmeqipVA0tSC3QhK3EMqbgtNpJqR/TpbfyWd9EFLS/Jc/kCkAbJlSDOi9ud
|
||||||
|
FkbnWBMiTtSPOiDwWMswbOdMTwHu+GxnAbB5+lQghxuEOTTmOPvEQ6DtYhpn
|
||||||
|
3+YIf0oDqeptjd+VE5Tx59CMV1RsZkbTVRJanBuLp339Kb/dfQi/G7mIkRne
|
||||||
|
hxUZ/Nx9LjsFxlcJRLnAnmtr5qfHeamo7ME=
|
||||||
|
=o+Va
|
||||||
|
-----END PGP SIGNATURE-----
|
||||||
|
|
@ -0,0 +1,18 @@
|
||||||
|
<?xml version="1.0" encoding="UTF-8"?>
|
||||||
|
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
|
||||||
|
|
||||||
|
<url>
|
||||||
|
<loc>https://k5bss.com/</loc>
|
||||||
|
<lastmod>2026-04-20</lastmod>
|
||||||
|
<changefreq>monthly</changefreq>
|
||||||
|
<priority>1.0</priority>
|
||||||
|
</url>
|
||||||
|
|
||||||
|
<url>
|
||||||
|
<loc>https://k5bss.com/k5bss.html</loc>
|
||||||
|
<lastmod>2026-04-20</lastmod>
|
||||||
|
<changefreq>weekly</changefreq>
|
||||||
|
<priority>0.8</priority>
|
||||||
|
</url>
|
||||||
|
|
||||||
|
</urlset>
|
||||||