Monday, 19 May 2014

X-Frame-Options response header

The X-Frame-Options HTTP response header can be used to indicate whether or not a browser should be allowed to render a page in a <frame>, <iframe> or <object> . Sites can use this to avoid clickjacking attacks, by ensuring that their content is not embedded into other sites.

Using X-Frame-Options

There are three possible values for X-Frame-Options:

  • DENY

    The page cannot be displayed in a frame, regardless of the site attempting to do so.

  • SAMEORIGIN

    The page can only be displayed in a frame on the same origin as the page itself.

  • ALLOW-FROM uri

    The page can only be displayed in a frame on the specified origin.

Read More>>

What is clickjacking?

What is Clickjacking and How can you prevent it?

No comments:

Post a Comment