Forum Discussion

Kash_276820's avatar
Kash_276820
Icon for Nimbostratus rankNimbostratus
Aug 23, 2017

ASM-custom-response-page Enable X-Frame-Option

ASM Experts, Is there any potential impact when we enable X-Frame-option deny/Sameorgin on ASM Custom Violation response page? Please advice .Thanks

 

3 Replies

  • Hello Kash,

     

    If your "custom response page" contains and you add :</p> <ul> <li>"X-Frame-Options: DENY" then the browser will not load the iframe content </li> <li>"X-Frame-Options: SAMEORIGIN" then browser will load only iframe comming from same domain</li> </ul> <p>If your "custom response page" doesn't contain iframe there is no impact to do this on the blocking page itself. </p> <p>Regards</p>

     

  • Should be no impact - these headers provide Clickjacking attack mitigation