国产老熟女高潮毛片A片仙踪林,欧美喂奶吃大乳,狠狠爱无码一区二区三区,女神的私人医生动漫免费阅读

新聞建站cms系統、政府cms系統定制開發

廣州網站建設公司-閱速公司

asp.net新聞發布系統、報紙數字報系統方案
/
http://www.tjsimaide.com/
廣州網站建設公司
您當前位置:首頁>網站技術

網站技術

X-Frame-Options Header未設置

發布時間:2017/6/1 11:45:03  作者:Admin  閱讀:758  

廣告:

X-Frame-Options Header未設置 (Clickjacking: X-Frame-Options header missing)

Severity: low

Type: Configuration

CWE:CWE-693 :Protection Mechanism Failure

Description

Clickjacking (User Interface redress attack, UI redress attack, UI redressing) is a malicious te chnique of tricking a Web user into clicking on something different from what the user perceives they are clicking on, thus potentially revealing confidential information or taking control of t heir computer while clicking on seemingly innocuous web pages.

The server didn't return an X-Frame-Options header which means that this website could be at ris k of a clickjacking attack. The X-Frame-Options HTTP response header can be used to indicate whe ther or not a browser should be allowed to render a page inside a frame or iframe. Sites can use this to avoid clickjacking attacks, by ensuring that their content is not embedded into other si tes.

Impact

The impact depends on the affected web application.

Recommendation

Configure your web server to include an X-Frame-Options header. Consult Web references for more information about the possible values for this header.

References

The X-Frame-Options response header

Clickjacking

OWASP Clickjacking

Defending with Content Security Policy frame-ancestors directive

Frame Buster Buster

Affected items

1.Impact target:Web Server

details:

No details are available. request:

GET / HTTP/1.1

Host: demo.53bk.com

Connection: Keep-alive

Accept-Encoding: gzip,deflate

User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chr ome/41.0.2228.0 Safari/537.21

Accept: */* response: HTTP/1.1 200 OK Server: Tengine

Date: Thu, 18 May 2017 09:12:19 GMT Content-Type: text/html; charset=gb2312

Content-Length: 16477

Cache-Control: public, max-age=561

Expires: Thu, 18 May 2017 09:21:40 GMT

Last-Modified: Thu, 18 May 2017 07:20:00 GMT X-AspNetMvc-Version: 2.0

X-AspNet-Version: 2.0.50727

X-Powered-By: ASP.NET

防止某些重要網頁被其他網站框架導入,可以給頁面增加X-Frame-Options響應頭

asp

<%

response.AddHeader "X-Frame-Options","Deny"

%>

Asp.Net

Response.AddHeader("X-Frame-Options", "Deny");

PHP

header('X-Frame-Options:Deny');

X-Frame-Options響應頭可用值有

DENY:瀏覽器拒絕當前頁面加載任何Frame頁面

SAMEORIGIN:frame頁面的地址只能為同源域名下的頁面

ALLOW-FROM:origin為允許frame加載的頁面地址

如果確認你整個網站都不能被框架,可以直接設置web服務器,增加X-Frame-Options響應頭。IIS如下圖所示,增加http頭

http頭名: X-Frame-Options

http頭值: SAMEORIGIN

廣告:

相關文章
X-Frame-Options
cms新聞系統購買咨詢
掃描關注 廣州閱速軟件科技有限公司
掃描關注 廣州閱速科技
主站蜘蛛池模板: 九台市| 铜陵市| 平南县| 昌宁县| 吴旗县| 和林格尔县| 元谋县| 阿克陶县| 扶沟县| 洛浦县| 和顺县| 华阴市| 怀集县| 濮阳县| 华容县| 旺苍县| 唐山市| 浮梁县| 彭山县| 全南县| 樟树市| 南涧| 虎林市| 桐乡市| 密云县| 安吉县| 和静县| 邯郸市| 奎屯市| 中卫市| 仙游县| 铜陵市| 青铜峡市| 芦山县| 镶黄旗| 家居| 乌拉特前旗| 龙泉市| 玉田县| 桐柏县| 海阳市|