Web Hack List

Later archive addition

XSS vulnerabilities in multiple iframe busters affecting top-tier sites

The research finds that common iframe-busting scripts copied across major sites read attacker-controlled location data and write it into executable page contexts. Framing a target with a crafted URL therefore converts defensive anti-framing code into reflected cross-site scripting on the protected origin.

Record

Researcher
Randy
Published by
Randy Westergren
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Randy, first published at the original source. Preserved copies are kept so the citation survives its host.