Activity Forums Salesforce® Discussions How Clickjacking Helps in securing Salesforce Visualforce Pages?

  • Subhendu

    Member
    January 24, 2018 at 8:55 am

    Hi Manpreet,

    Clickjacking is a type of attack that tries to trick a user into clicking something, maybe a button or link, because they perceive they are clicking something safe. Instead, the button or link performs malicious actions on your site leading to data intrusion, unauthorized emails, changed credentials, or other site-specific actions.

    There are a two commonly employed techniques to prevent clickjacking - frame-busting scripts and the X-Frame Options header. Salesforce leverages both of the methods as standard clickjacking protection. You can view your protection settings in Setup. Enter Session Settings in the Quick Find box, then select Session Settings. By default all standard Salesforce pages are protected against clickjacking; If not, you can contact Salesforce Support to enable it in your Org.

    Hope this helps.

    Thanks,
    Subhendu

Log In to reply.

Popular Salesforce Blogs

Popular Salesforce Videos