SummerOfCode/2013/SecurityReport/WeeklyUpdates/2013-07-22: Difference between revisions

Line 12: Line 12:
** X-Frame-Options Header
** X-Frame-Options Header
*** I also read about "X-Frame-Options" header and checked whether it is used by website or not. If not then appropriate message is displayed in the security report tool's "Sec-Headers" Tab.  Absent of "X-Frame-Option" header means site is vulnerable to Clickjacking attacks.
*** I also read about "X-Frame-Options" header and checked whether it is used by website or not. If not then appropriate message is displayed in the security report tool's "Sec-Headers" Tab.  Absent of "X-Frame-Option" header means site is vulnerable to Clickjacking attacks.
[[File:sec-headers.png]]
Confirmed users
461

edits