亚洲3P视频,日韩BBW无码,亚洲制服麻豆网站,88re伊人,九草精品视频在线观看,国产精品久久夜,色青青狠狠色,无码熟女一区二区三区,日本一区二区成人网站

新聞建站cms系統(tǒng)、政府cms系統(tǒng)定制開發(fā)

廣州網(wǎng)站建設(shè)公司-閱速公司

asp.net新聞發(fā)布系統(tǒng)、報(bào)紙數(shù)字報(bào)系統(tǒng)方案
/
http://m.duxiu2008.cn/
廣州網(wǎng)站建設(shè)公司
您當(dāng)前位置:首頁(yè)>網(wǎng)站技術(shù)

網(wǎng)站技術(shù)

X-Frame-Options Header未設(shè)置

發(fā)布時(shí)間:2017/6/1 11:45:03  作者:Admin  閱讀:825  

廣告:

X-Frame-Options Header未設(shè)置 (Clickjacking: X-Frame-Options header missing)

Severity: low

Type: Configuration

CWE:CWE-693 :Protection Mechanism Failure

Description

Clickjacking (User Interface redress attack, UI redress attack, UI redressing) is a malicious te chnique of tricking a Web user into clicking on something different from what the user perceives they are clicking on, thus potentially revealing confidential information or taking control of t heir computer while clicking on seemingly innocuous web pages.

The server didn't return an X-Frame-Options header which means that this website could be at ris k of a clickjacking attack. The X-Frame-Options HTTP response header can be used to indicate whe ther or not a browser should be allowed to render a page inside a frame or iframe. Sites can use this to avoid clickjacking attacks, by ensuring that their content is not embedded into other si tes.

Impact

The impact depends on the affected web application.

Recommendation

Configure your web server to include an X-Frame-Options header. Consult Web references for more information about the possible values for this header.

References

The X-Frame-Options response header

Clickjacking

OWASP Clickjacking

Defending with Content Security Policy frame-ancestors directive

Frame Buster Buster

Affected items

1.Impact target:Web Server

details:

No details are available. request:

GET / HTTP/1.1

Host: demo.53bk.com

Connection: Keep-alive

Accept-Encoding: gzip,deflate

User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chr ome/41.0.2228.0 Safari/537.21

Accept: */* response: HTTP/1.1 200 OK Server: Tengine

Date: Thu, 18 May 2017 09:12:19 GMT Content-Type: text/html; charset=gb2312

Content-Length: 16477

Cache-Control: public, max-age=561

Expires: Thu, 18 May 2017 09:21:40 GMT

Last-Modified: Thu, 18 May 2017 07:20:00 GMT X-AspNetMvc-Version: 2.0

X-AspNet-Version: 2.0.50727

X-Powered-By: ASP.NET

防止某些重要網(wǎng)頁(yè)被其他網(wǎng)站框架導(dǎo)入,可以給頁(yè)面增加X-Frame-Options響應(yīng)頭

asp

<%

response.AddHeader "X-Frame-Options","Deny"

%>

Asp.Net

Response.AddHeader("X-Frame-Options", "Deny");

PHP

header('X-Frame-Options:Deny');

X-Frame-Options響應(yīng)頭可用值有

DENY:瀏覽器拒絕當(dāng)前頁(yè)面加載任何Frame頁(yè)面

SAMEORIGIN:frame頁(yè)面的地址只能為同源域名下的頁(yè)面

ALLOW-FROM:origin為允許frame加載的頁(yè)面地址

如果確認(rèn)你整個(gè)網(wǎng)站都不能被框架,可以直接設(shè)置web服務(wù)器,增加X-Frame-Options響應(yīng)頭。IIS如下圖所示,增加http頭

http頭名: X-Frame-Options

http頭值: SAMEORIGIN

廣告:

相關(guān)文章
X-Frame-Options
cms新聞系統(tǒng)購(gòu)買咨詢
掃描關(guān)注 廣州閱速軟件科技有限公司
掃描關(guān)注 廣州閱速科技
大连市| 斗六市| 楚雄市| 亚东县| 出国| 融水| 高尔夫| 阿拉善右旗| 当阳市| 防城港市| 双流县| 泊头市| 荆州市| 兴城市| 溧水县| 华容县| 瑞昌市| 玉环县| 安国市| 渝中区| 镇巴县| 如皋市| 宁武县| 洞头县| 类乌齐县| 武胜县| 芜湖市| 苏州市| 哈密市| 仁布县| 万源市| 东阿县| 托克逊县| 沅江市| 五台县| 怀安县| 太仆寺旗| 罗甸县| 萝北县| 靖西县| 文登市|