RE: X-FRame-Option

2015-10-30 Thread Walsh, Joseph
From: Mark Eggers [mailto:its_toas...@yahoo.com.INVALID] Sent: Thursday, October 29, 2015 7:38 PM To: Tomcat Users List Subject: Re: X-FRame-Option -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Joseph, As per list conventions, I'm posting at the bottom. I'll copy over the relevant parts

Re: X-FRame-Option

2015-10-29 Thread Mark Eggers
quot;security Center" by Tenable-- > complaining --server is not returning x-frame-option heading -- I > can confirm this with Mozilla firebug.. > > within the tomcat\conf\web.xml file there is "built in filters" > > as I have configured below: (thinking maybe &qu

Re: X-FRame-Option

2015-10-29 Thread Konstantin Kolinko
2015-10-29 23:03 GMT+03:00 Walsh, Joseph : > Konstantin good afternoon .. > > my servers are being scanned by a "security Center" by Tenable-- > complaining --server is not returning x-frame-option heading -- > I can confirm this with Mozilla firebug.. > > with

RE: X-FRame-Option

2015-10-29 Thread Walsh, Joseph
Konstantin good afternoon .. my servers are being scanned by a "security Center" by Tenable-- complaining --server is not returning x-frame-option heading -- I can confirm this with Mozilla firebug.. within the tomcat\conf\web.xml file there is "built in filters" as I h

Re: X-FRame-Option

2015-10-29 Thread Konstantin Kolinko
> > Anyone have any luck adding the X-Frame-Option in a windows environment? > I have tried using the built in filter with no luck ...seems plenty of fixes > but all I find seems to be geared towards a Unix install... > currently running Apache Tomcat vers 8.0.26 If you expect other

X-FRame-Option

2015-10-29 Thread Walsh, Joseph
good afternoon all... I have been recently been "relocated" within our IT dept and now tasked with supporting Apache Tomcat on windows... Our cyber dept scanner has identified my app as vulnerable to clickjacking ... Anyone have any luck adding the X-Frame-Option in a windows envi