Web Hack List

Collected research

A Tale of Two Headers: A Formal Analysis of Inconsistent Click-Jacking Protection on the Web

Framing control is split between X-Frame-Options and CSP frame-ancestors, which browsers implement differently. A formal model and an automated policy analyser found ten percent of distinct framing policies in the wild inconsistent, usually leaving at least one browser with no clickjacking protection, and a server-side proxy is proposed to retrofit a consistent policy.

Record

Researcher
Stefano Calzavara, Sebastian Roth, Alvise Rabitti, Michael Backes and Ben Stock
Published by
usenix.org
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Stefano Calzavara, Sebastian Roth, Alvise Rabitti, Michael Backes and Ben Stock, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .