Monday, 2014-09-08

*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid12:53
*** immotus_ (~immotus@rrcs-24-153-193-34.sw.biz.rr.com) has joined #wikid16:35
immotus_PCI Compliance season for us again!  I need to add an HTTP response header that makes it difficult to use the "Click Jacking" attack vector.  Is there a place where I can add that for our WiKID installation (wikid-server-enterprise-3.6.0.b1659-1)?     Click Jacking explanation -https://www.owasp.org/index.php/Clickjacking16:44
immotus_in Apache I add the following line to the apache config file..       Header always append X-Frame-Options SAMEORIGIN16:48
immotus_nevermind.. apparently I was adding it to the wrong place in the apache config that forwarded to the WiKID tomcat server16:53
immotus_when i add it to /etc/httpd/conf/httpd.conf the header shows up just fine16:53
nowenimmotus_: are you running apache on the same server as WiKID?16:55
immotus_nowen: yes.. it's forwarding to WiKID.. I don't know why it was setup that way.   Anyways, I see the response header now17:15
immotus_nowen: apparently, if we weren't going through apache to Tomcat, the solution would involve a "servlet filter" of some sort to add the "X-Frame-Options SAMEORIGIN" response header somehow17:16
nowenyeah,17:18
nowenmakes sense.17:18
nowenas long as you know what you're doing ;-)17:19
immotus_nowen: heh :^)17:21
nowenbiab, got to grab some lunch17:41
*** nowen is now known as nowen_lunch17:41
*** nowen_lunch is now known as nowen18:15
*** immotus_ has parted #wikid ("Konversation terminated!")21:26
*** nowen has quit (Quit: Leaving.)22:10
*** Qasker has quit (Quit: QQQuit:)22:35

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!