X-Content-Type-Options
This header stops browsers from guessing the type of a file, closing a trick attackers use to make harmless-looking files run as code.
What it is
Browsers sometimes try to guess the real type of a file if the server's declared type looks wrong — a process called MIME sniffing. The X-Content-Type-Options header with the value nosniff tells the browser to stop guessing and trust the declared type exactly.
It's a small, one-line header with no downside, and it removes a whole category of confusion-based attacks.
Why it matters
MIME sniffing can be abused: an attacker uploads a file that looks like an image but contains script, and hopes the browser "sniffs" it as executable code. With nosniff, the browser respects the declared type and refuses to run it as something else.
How Pentrawl checks it
Pentrawl checks your response headers for X-Content-Type-Options. If it's set (to nosniff), the check passes; if missing, it's flagged as an issue.
How to fix it
Add the header to your server configuration. There is only one meaningful value, and it should always be set.
X-Content-Type-Options: nosniff