4 ms·
Actually X-Frame-Options does not save you here. There is a BYPASS_XFO datastore option in the module that turns this into a one-click exploit. This allows the
by joev_ 12y ago
Actually X-Frame-Options does not save you here. There is a BYPASS_XFO datastore option in the module that turns this into a one-click exploit. This allows the attack to work against sites with the XFO header.
- steakejjs 12y agoAbsolutely critical to know. Thanks joev_. I see that now after reading the msfmodule. This is a good one!