Tomcat 点击劫持漏洞修改

修改 tomcat 的点击劫持漏洞

一、修改 tomcat 的 web.xml 配置文件

修改web服务器配置,添加X-Frame-Options响应头。赋值有如下三种:
1、DENY:不能被嵌入到任何iframe或者frame中
2、SAMEORIGIN:页面只能被本站页面嵌入到iframe或者frame中
3、ALLOW-FROM Uri:只能被嵌入到指定域名的框架中

<filter>
    <filter-name>httpHeaderSecurityfilter-name>
    <filter-class>org.apache.catalina.filters.HttpHeaderSecurityFilterfilter-class>
    param>
        <param-name>antiClickJackingEnabledparam-name>
        <param-value>trueparam-value>
    param>
    param>
        <param-name>antiClickJackingOptionparam-name>
        <param-value>SAMEORIGINparam-value>
    param>
    true
filter>
<filter-mapping>
    <filter-name>httpHeaderSecurityfilter-name>
    /*

你可能感兴趣的:(Tomcat漏洞)