zhukov / webogram

Telegram web application, GPL v3
https://web.telegram.org
GNU General Public License v3.0
7.96k stars 2.36k forks source link

Webogram JS Clickjacking busting bypass #1127

Closed SymbianSyMoh closed 8 years ago

SymbianSyMoh commented 8 years ago

Hi, Here's more details: https://www.seekurity.com/blog/general/telegram-web-client-clickjacking-vulnerability/

ingria commented 8 years ago

The Fix: This bug has been fixed now, Telegram Web Client applied “X-Frame-Options” header on server side!

SymbianSyMoh commented 8 years ago

Hi @codefuhrer I'm the reporter of the bug and sure I know that they have fixed it, But regarding Webogram, It has to have a mitigation in place by adding a user caution or a configuration option to apply the header by default!