Just for fun

Security Audit

Four real response headers, one of them wrong. Click it before the 10-second clock runs out — one mistake ends the run.

time left10sscore0best
</> Response Headers

How to play

ObjectiveEach round shows 4 real header or cookie lines — exactly one is genuinely wrong or insecure. Click it before the 10-second timer runs out.
ScoringA correct spot advances to a new scenario automatically; a wrong click or a timeout ends the run and reveals the real answer.
The contentEvery scenario is a real, documented misconfiguration — things like an invalid X-Frame-Options value, a disabled HSTS max-age, a Set-Cookie missing the Secure flag, or an overly permissive CORS wildcard — not invented gibberish.