5up3rh3iblog has been rampant in recent years, leading to the disruption of the traditional security concept... it is a headache for defense. Fortunately, the cool people who are keen on the wretched stream are also thinking about how to defend against the security problems that are headaches. For example:
Clickjacking<--- X --- X-Frame-Options
XSS <--- x --- X-XSS-Protection
Recently, anotherX-Content-Type-OptionsUsed for DefenseMIME-sniffingClass.
In these cases, X-Frame-Options has a major impact on security, because access to external domains such as iframe is prohibited, which not only defends against Clickjacking, at the same time, non-stored xss cannot be called through iframe on the 3rd side page. In addition, headers such as google have been deployed on major websites recently. In addition, the various browsers of these headers also began to respond to the support ......
It seems that the future security trend is: No, no more, no more !!!!!