Skip to content
This repository has been archived by the owner on Jan 1, 2023. It is now read-only.

Finding on 2018-01-30 04:26:16 #6

Open
ivanchoo opened this issue Jul 30, 2018 · 0 comments
Open

Finding on 2018-01-30 04:26:16 #6

ivanchoo opened this issue Jul 30, 2018 · 0 comments

Comments

@ivanchoo
Copy link
Owner

  • Name: X-Frame-Options Header Not Set
  • ID: 4e8c8d0b607d35ef212e3040718672eb
  • Affected Hosts: ['https://uod-offroad.com/']
  • Description: X-Frame-Options header is not included in the HTTP response to protect against 'ClickJacking' attacks.
  • First seen: 2018-01-30 04:26:16
  • Recommendation: Most modern Web browsers support the X-Frame-Options HTTP header. Ensure it's set on all web pages returned by your site (if you expect the page to be framed only by pages on your server (e.g. it's part of a FRAMESET) then you'll want to use SAMEORIGIN, otherwise if you never expect the page to be framed, you should use DENY. ALLOW-FROM allows specific websites to frame the web page in supported web browsers).
  • Source Link: https://staging.horangi.com/storyfier/detect/29e9012a-6624-456e-85ce-af2eb79e51d0/4e8c8d0b607d35ef212e3040718672eb
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant