3 ms·
I believe that would be the point of <meta http-equiv="X-Frame-Options" content="deny">
by snikch 13y ago
I believe that would be the point of <meta http-equiv="X-Frame-Options" content="deny">
- codygman 13y agoThat's like trying to duct tape your arm back on after losing a fight with a chainsaw.
- mike-cardwell 13y ago<img src="https://accounts.google.com/Logout" https://accounts.google.com/Logout" style="display:none"> "X-Frame-Options" is used to defend against click-jacking attacks, not to defend against CSRF.