Nytro Posted December 18, 2013 Report Posted December 18, 2013 X-Frame-Options: All about Clickjacking?“How else do X-Frame-Options protect my website”A poem by Frederik Braun (Mozilla) and Mario Heiderich (Cure53)The X-Frame-Options header is known to be a good measurement against those socalled Clickjacking attacks. You know, this kind of attack where some other websiteloads important parts of your website inside an Iframe or even frameset, makeseverything invisible and overlays attractive looking links and buttons with your invisiblewebsite. But - is it really all about Clickjacking? Let us find out about that!I. IntroductionII. The Docmode - ProblemIII. Drag ’ N ’ Drop XSSIV. Copy & Paste XSSV. Invisible Site - Wide XSSVI. Cross - Site Scripting & Length RestrictionsVII. JavaScript à la CarteVIII. Frame BustingIX. Side Channels & Cross - Origin LeaksX. Bye bye , CSPXI. ConclusionDownload:https://frederik-braun.com/xfo-clickjacking.pdf Quote