Y
Hacker News
new
|
ask
|
show
|
jobs
by
jffry
4700 days ago
Just threw together a test case. X-Frame-Options does seem to mitigate the view-source attack:
http://jsfiddle.net/GEynT/2/embedded/result/
1 comments
joshfraser
4700 days ago
To be clear, the hack is still possible without view-source. It just makes it easier and more generic of a solution.
link