In order to improve the security of your site against ClickJacking, it is recommended that you add the following header to your site:
It is supported by all browsers and prevents an attacker from iframing the content of your site into others.
This article from Mozilla explains it in detail: On the X-Frame-Options Security Header
Enabling this header
You can enable it by modifying your Apache settings or your inserting the following code into your
Header always append X-Frame-Options SAMEORIGIN
Note: this is enabled by default.
You can enable it on your WAF (along with other security headers) by setting “Additional Security Headers ” to on.
If you have any questions, please contact our research team at firstname.lastname@example.org.