Later archive addition
XSS vulnerabilities in multiple iframe busters affecting top-tier sites
The research finds that common iframe-busting scripts copied across major sites read attacker-controlled location data and write it into executable page contexts. Framing a target with a crafted URL therefore converts defensive anti-framing code into reflected cross-site scripting on the protected origin.
Record
- Researcher
- Randy
- Published by
- Randy Westergren
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Randy, first published at the original source. Preserved copies are kept so the citation survives its host.