Skip to content

Scam Alert: False Vulnerability Reports from "Security Researchers" Using X-Frame-Bypass Library #53

@pauliusjacionis

Description

@pauliusjacionis

Hello everyone,

I recently received an email from a "security researcher" who used the X-Frame-Bypass library to report an "X-Frame-Options bypass bug". They were expecting a bug bounty payment.

I want to draw attention to this: the library DOES NOT actually bypass X-Frame-Options; it only creates the illusion of a bypass. Because traffic is proxied through a different domain name, session data and cookies are lost. This "bypass" is entirely harmless.

Be cautious of bug bounty scams and fraudulent security researchers.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions