top | item 8321857

(no title)

joev_ | 11 years ago

Actually X-Frame-Options does not save you here. There is a BYPASS_XFO datastore option in the module that turns this into a one-click exploit. This allows the attack to work against sites with the XFO header.

discuss

order

steakejjs|11 years ago

Absolutely critical to know. Thanks joev_. I see that now after reading the msfmodule. This is a good one!