Security Web - dennisholee/notes GitHub Wiki

iFrame

  • Embed another HTML document into the current one.
  • May hide malicious content in iFrames that appear to operate as normal for your customer’s experience.
  • Misuse of iframes has given rise to attacks including, displaying unauthorized content, malvertising, clickjacking, and cross-site scripting.

Sandbox iFrame

https://go.talasecurity.io/iframe-sandboxing