iframe

1 article
sort: new top best
clear filter
0 6/10

Researcher discovered a clickjacking vulnerability on Binary.com's ticktrade subdomain that lacked X-Frame-Options protection, then bypassed the initial JavaScript frame-busting patch by using HTML5 sandboxed iframes with permissive attributes (allow-scripts, allow-forms, allow-same-origin) to prevent top-level navigation while maintaining script execution.

Binary.com Binary Ltd ticktrade.binary.com Ameer Assadi
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 11 hours ago · details