The Clickjacking attack, X-Frame-Options
Posted by jpluimers on 2015/04/29
Front-end web development isn’t my core area of expertise, but every now and then I am slightly more than the usual spectator and do get involved.
This case it was about helping to prevent The Clickjacking attack by using the The X-Frame-Options response header from RFC 7034.
Lots of people seem to have questions about it: Highest Voted ‘x-frame-options’ Questions – Stack Overflow.
So, from The X-Frame-Options response header:
There are three possible values for X-Frame-Options:
DENY- The page cannot be displayed in a frame, regardless of the site attempting to do so.
SAMEORIGIN- The page can only be displayed in a frame on the same origin as the page itself.
ALLOW-FROM uri- The page can only be displayed in a frame on the specified origin.
–jeroen
via:






Leave a comment