EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium

A web developer is implementing a feature that allows users to embed content from other websites (e.g., YouTube videos, social media feeds) into their personal profiles. To mitigate the risk of Cross-Site Scripting (XSS) and other content injection attacks from potentially untrusted external sources, which HTML5 security attribute should be primarily utilized in the `<iframe>` tag?

  1. Asrcdoc
  2. Bsandbox
  3. Callowfullscreen
  4. Dloading
Show answer & explanation

Correct answer: B. sandbox

The `sandbox` attribute in an `<iframe>` creates a restricted environment for the embedded content, preventing it from executing scripts, submitting forms, accessing cookies, and navigating the parent frame, which is crucial for mitigating XSS and content injection from untrusted sources.

Why the other options are wrong

  • A. The `srcdoc` attribute specifies the HTML content of the page to show in the iframe, which is not primarily for security against external embeds.
  • C. The `allowfullscreen` attribute permits the iframe content to use fullscreen mode, not a security control.
  • D. The `loading` attribute specifies how the browser should load the iframe (e.g., 'lazy'), which is for performance, not security.

Iframe Sandboxing

Iframe sandboxing, using the HTML5 `sandbox` attribute, creates a highly restricted environment for content embedded within an `<iframe>` element.

  • Prevents embedded content from executing scripts, accessing parent DOM, or submitting forms.
  • Mitigates Cross-Site Scripting (XSS) and other content injection attacks.
  • Specific 'allow' flags can selectively re-enable certain functionalities.

Memory trick: Frames Secure, Content Contained.

More Web Application Hacking questions