{"id":19060,"date":"2017-04-13T06:01:53","date_gmt":"2017-04-13T05:01:53","guid":{"rendered":"https:\/\/jurnsearch.wordpress.com\/?p=19060"},"modified":"2017-04-13T06:01:53","modified_gmt":"2017-04-13T05:01:53","slug":"anti-click-jacking","status":"publish","type":"post","link":"https:\/\/jurn.link\/jurnsearch\/index.php\/2017\/04\/13\/anti-click-jacking\/","title":{"rendered":"Anti click-jacking code"},"content":{"rendered":"<p>For your Web page, here&#8217;s strong anti-framejacking and anti-clickjacking code, which has been tested and currently busts nasty frame-jackers such as In.is (aka Linkis).  As such these snippets may be useful for journals and other academic services, to prevent legitimate content from being hijacked and surrounded by frames advertising &#8216;essay-writing services&#8217; or predatory publisher services or worse.<\/p>\n<p><a href=\"https:\/\/jurn.link\/jurnsearch\/2017\/04\/clickcode.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/jurn.link\/jurnsearch\/2017\/04\/clickcode.jpg\" alt=\"\" width=\"529\" height=\"162\" class=\"alignnone size-large wp-image-19066\" \/><\/a><\/p>\n<p>Source: <a href=\"https:\/\/seclab.stanford.edu\/websec\/framebusting\/index.php\">Stanford Security Lab<\/a> via a recent blog post by <a href=\"https:\/\/ziplineinteractive.com\/blog\/how-to-prevent-a-website-from-being-loaded-in-an-iframe\/\">Zipline Interactive<\/a>, where there&#8217;s also additional defensive code to add to your website&#8217;s root .htaccess file (if you have FTP access <em>and<\/em> your host will allow upload of a changed .htaccess)&#8230;<\/p>\n<p><code>Header set X-Frame-Options SAMEORIGIN<\/code><\/p>\n<p>The .htaccess code is &#8216;as well as&#8217;, serving as a second line of deeper defence, and is not required for the first code suggestion to work in your Web page.  Most modern Web browsers understand the self-explanatory SAMEORIGIN command when they hear it from a website.<\/p>\n<p>Those with a hosted WordPress blog or journal may also want to consider the <a href=\"https:\/\/wordpress.org\/plugins\/frame-buster\/\">Frame Buster plugin<\/a>.  So far as I know there&#8217;s nothing similar for the Open Journal System (OJS) or Omeka or similar academic content plug-and-play systems.  But perhaps there should be, if they don&#8217;t already have such counter-measures baked in?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>For your Web page, here&#8217;s strong anti-framejacking and anti-clickjacking code, which has been tested and currently busts nasty frame-jackers such &hellip;<\/p>\n<p><a href=\"https:\/\/jurn.link\/jurnsearch\/index.php\/2017\/04\/13\/anti-click-jacking\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-19060","post","type-post","status-publish","format-standard","hentry","category-jurn-tips-and-tricks"],"_links":{"self":[{"href":"https:\/\/jurn.link\/jurnsearch\/index.php\/wp-json\/wp\/v2\/posts\/19060","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jurn.link\/jurnsearch\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jurn.link\/jurnsearch\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jurn.link\/jurnsearch\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jurn.link\/jurnsearch\/index.php\/wp-json\/wp\/v2\/comments?post=19060"}],"version-history":[{"count":0,"href":"https:\/\/jurn.link\/jurnsearch\/index.php\/wp-json\/wp\/v2\/posts\/19060\/revisions"}],"wp:attachment":[{"href":"https:\/\/jurn.link\/jurnsearch\/index.php\/wp-json\/wp\/v2\/media?parent=19060"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jurn.link\/jurnsearch\/index.php\/wp-json\/wp\/v2\/categories?post=19060"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jurn.link\/jurnsearch\/index.php\/wp-json\/wp\/v2\/tags?post=19060"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}