[ GF.dev ] All Tools →

Learn

Comprehensive guides on web security, server administration, and network diagnostics. Each guide links directly to free tools so you can test as you learn.

Guides

The Complete Guide to HTTP Security Headers

Master HTTP security headers: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, and more. Learn to configure, test, and audit headers for Nginx and Apache.

Published 2026-03-29 · Modified 2026-03-29 · 7 articles

SSL/TLS Configuration Guide: Securing Your Web Server from Scratch

Complete guide to SSL/TLS configuration. Learn TLS 1.3, cipher suites, HTTPS migration, certificate types, and how to score A+ on SSL Labs.

Published 2026-03-29 · Modified 2026-03-29 · 5 articles

DNS for Web Developers: Everything You Need to Know

A comprehensive guide to DNS for web developers and sysadmins. Learn how DNS works, record types, propagation, Whois, email authentication, DNSSEC, and more.

Published 2026-03-29 · Modified 2026-03-29 · 5 articles

Web Server Performance Troubleshooting: A Sysadmin's Playbook

Master web server performance troubleshooting with this comprehensive guide covering TTFB, HTTP headers, caching strategies, CDN configuration, and server diagnostics tools.

Published 2026-03-29 · Modified 2026-03-29 · 5 articles

The WordPress Security Hardening Checklist

A comprehensive WordPress security hardening checklist covering login protection, plugin security, file permissions, database hardening, WAF configuration, and vulnerability scanning. Free tools included.

Published 2026-03-29 · Modified 2026-03-29 · 5 articles

Recent Articles

What is HSTS and How to Configure It Properly

Part of The Complete Guide to HTTP Security Headers · Published 2026-03-29 · Modified 2026-03-29

Content Security Policy (CSP) Explained: From Basics to Advanced

Part of The Complete Guide to HTTP Security Headers · Published 2026-03-29 · Modified 2026-03-29

Preventing Clickjacking with X-Frame-Options and CSP frame-ancestors

Part of The Complete Guide to HTTP Security Headers · Published 2026-03-29 · Modified 2026-03-29

X-Content-Type-Options: Why MIME Sniffing is Dangerous

Part of The Complete Guide to HTTP Security Headers · Published 2026-03-29 · Modified 2026-03-29

XSS Protection Headers: What Still Works in 2026

Part of The Complete Guide to HTTP Security Headers · Published 2026-03-29 · Modified 2026-03-29

How to Audit Your Security Headers in 5 Minutes

Part of The Complete Guide to HTTP Security Headers · Published 2026-03-29 · Modified 2026-03-29

Cookie Security: Secure, HttpOnly, SameSite Explained

Part of The Complete Guide to HTTP Security Headers · Published 2026-03-29 · Modified 2026-03-29

TLS Cipher Suites Ranked: Which to Enable, Which to Disable

Part of SSL/TLS Configuration Guide: Securing Your Web Server from Scratch · Published 2026-03-29 · Modified 2026-03-29