<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: IFrames security summary</title>
	<atom:link href="http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Mon, 15 Mar 2010 06:32:06 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-1457</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 10 Feb 2009 00:08:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-1457</guid>
		<description>@Gunner

The use of iframes on your web site is not a security risk as long as you are not referencing external sites. 

The point of this article was to highlight how iframes and their functionality can be used in ways in which wasn't intended</description>
		<content:encoded><![CDATA[<p>@Gunner</p>
<p>The use of iframes on your web site is not a security risk as long as you are not referencing external sites. </p>
<p>The point of this article was to highlight how iframes and their functionality can be used in ways in which wasn&#8217;t intended</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gunner</title>
		<link>http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-1456</link>
		<dc:creator>Gunner</dc:creator>
		<pubDate>Mon, 09 Feb 2009 22:28:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-1456</guid>
		<description>I'm debating the use of iframes and security is my main concern. The iframe would reference other pages at our site not external pages. But I'm trying to figure out how using iframes on my site is a security risk. It seems that iframes themselves do not have security flaws. How would someone exploit an iframe on my site if my site is not compromised and I clean all user input of any html so they cannot inject an iframe. It seems to me some other aspect of a website has to fail before an iframe can be used in a malicious way. And in those cases it is not the site's iframes that are used, but iframes created by the attacker. Is there something I'm missing? I appreciate the article, just trying to make sure I understand iframes.</description>
		<content:encoded><![CDATA[<p>I&#8217;m debating the use of iframes and security is my main concern. The iframe would reference other pages at our site not external pages. But I&#8217;m trying to figure out how using iframes on my site is a security risk. It seems that iframes themselves do not have security flaws. How would someone exploit an iframe on my site if my site is not compromised and I clean all user input of any html so they cannot inject an iframe. It seems to me some other aspect of a website has to fail before an iframe can be used in a malicious way. And in those cases it is not the site&#8217;s iframes that are used, but iframes created by the attacker. Is there something I&#8217;m missing? I appreciate the article, just trying to make sure I understand iframes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-1412</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 15 Jan 2009 18:08:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-1412</guid>
		<description>@Bruce LOL are you a advertising network by any chance? If not explain why it is hogwash with some detailed examples.</description>
		<content:encoded><![CDATA[<p>@Bruce LOL are you a advertising network by any chance? If not explain why it is hogwash with some detailed examples.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bruce</title>
		<link>http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-1411</link>
		<dc:creator>Bruce</dc:creator>
		<pubDate>Thu, 15 Jan 2009 18:00:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-1411</guid>
		<description>I'm sorry but your iframes rant is pretty much all hogwash. You should stop with the spreading of this type of misinformation. All of those scenarios are quite childish and don't in any case define any real security threat. In fact all of the scenarios can be attempted with just straight html. There are millions of iframes in use today. there is no evidence that they are a heightened security risk.</description>
		<content:encoded><![CDATA[<p>I&#8217;m sorry but your iframes rant is pretty much all hogwash. You should stop with the spreading of this type of misinformation. All of those scenarios are quite childish and don&#8217;t in any case define any real security threat. In fact all of the scenarios can be attempted with just straight html. There are millions of iframes in use today. there is no evidence that they are a heightened security risk.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sreekanth</title>
		<link>http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-1318</link>
		<dc:creator>Sreekanth</dc:creator>
		<pubDate>Wed, 24 Sep 2008 06:09:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-1318</guid>
		<description>Great brief. I am a beginner and did not know all these things could be done.</description>
		<content:encoded><![CDATA[<p>Great brief. I am a beginner and did not know all these things could be done.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bipin 3~ Upadhyay</title>
		<link>http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-763</link>
		<dc:creator>Bipin 3~ Upadhyay</dc:creator>
		<pubDate>Sat, 27 Oct 2007 08:58:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-763</guid>
		<description>@Mat:
Just to add to what Gareth said, you can use "security=restricted" parameter to bypass it in IE.
http://crypto.stanford.edu/framebust/</description>
		<content:encoded><![CDATA[<p>@Mat:<br />
Just to add to what Gareth said, you can use &#8220;security=restricted&#8221; parameter to bypass it in IE.<br />
<a href="http://crypto.stanford.edu/framebust/" rel="nofollow">http://crypto.stanford.edu/framebust/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-761</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 26 Oct 2007 10:31:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-761</guid>
		<description>Yep actually I do recommend that on my blog. Only downside is that with IE it is possible to get round it.</description>
		<content:encoded><![CDATA[<p>Yep actually I do recommend that on my blog. Only downside is that with IE it is possible to get round it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mat</title>
		<link>http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-760</link>
		<dc:creator>mat</dc:creator>
		<pubDate>Fri, 26 Oct 2007 10:05:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-760</guid>
		<description>Is a simple script like this one a good protection against iframe attacks  :

&#60;script type="text/javascript"&#62;
if (top != self)
top.location.href = location.href;
&#60;/script&#62;

Thanks.</description>
		<content:encoded><![CDATA[<p>Is a simple script like this one a good protection against iframe attacks  :</p>
<p>&lt;script type=&#8221;text/javascript&#8221;&gt;<br />
if (top != self)<br />
top.location.href = location.href;<br />
&lt;/script&gt;</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-755</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Wed, 24 Oct 2007 18:37:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-755</guid>
		<description>Thanks Marco :)</description>
		<content:encoded><![CDATA[<p>Thanks Marco <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marco Ramilli</title>
		<link>http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-754</link>
		<dc:creator>Marco Ramilli</dc:creator>
		<pubDate>Wed, 24 Oct 2007 17:25:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/10/24/iframes-security-summary/#comment-754</guid>
		<description>Yep, great brief Gareth.
Thanks.</description>
		<content:encoded><![CDATA[<p>Yep, great brief Gareth.<br />
Thanks.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
