The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Missing legal value in "Frameable responce (potential Clickjacking)"

Alf-Ivar | Last updated: Dec 10, 2015 03:36PM UTC

The "Remediation detail" claims: "The X-Frame-Options header should only have one of the expected values: DENY or SAMEORIGIN." That used to be the case, but today even: "ALLOW-FROM <url>" is allowed, as described in the Mozilla-page under References. According to OWASP ALLOW-FROM has been around since 2012: https://www.owasp.org/index.php/Clickjacking_Defense_Cheat_Sheet#Limitations_2 The caution mentioned in the OWASP article is valid, but the current "Issue detail" is not true: "The response contains an X-Frame-Options header with an unexpected value. Browsers will ignore this header and allow the response to be framed." Regards, Affi

PortSwigger Agent | Last updated: Dec 16, 2015 11:44AM UTC