How to verify if clickjacking Xframe is enabled or disabled
search cancel

How to verify if clickjacking Xframe is enabled or disabled

book

Article ID: 218448

calendar_today

Updated On:

Products

CA Privileged Identity Management Endpoint (PIM)

Issue/Introduction

How to check if clickjacking Xframe is enabled or disabled in CA PAMSC 14.x release

Environment

Release: 14.1

Component : SYMANTEC PRIVILEGED ACCESS MANAGER SERVER CONTROL - 14.1

Cause

If Clickjacking is enabled it can pose a serious security threat to the organization.

Clickjacking, also known as a “UI redress attack”, is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top-level page. Thus, the attacker is “hijacking” clicks meant for their page and routing them to another page, most likely owned by another application, domain, or both.

Resolution

In the PAMSC 14.x release Clickjacking is disabled by default.

This is displayed in the screenshot below, look at the XFrames-Option

Attachments