Check for know iframeBuster XSS
A couple of month later:
Today:
$ gem install faraday $ gem install logger $ gem install optparse $ git clone https://github.com/tr4l/iframeBusterXSS.git
$ ./check.rb -r http://perdu.com/
If you use that succesfully for your pentest work and/or bug bounty with monetary rewards, this is mandatory to pay me a beer at the next event we will be together.