mirror of
https://github.com/gorhill/uBlock.git
synced 2026-03-11 09:04:36 +00:00
Updated Dynamic filtering: Benefits of blocking 3rd party iframe tags (markdown)
parent
641c84f456
commit
7b7835cc8d
1 changed files with 2 additions and 2 deletions
|
|
@ -18,7 +18,7 @@ Using 3rd-party-sourced `<iframe>` to inject exploit on a user's computer is qui
|
|||
|
||||
<p align="center"><img src="https://cloud.githubusercontent.com/assets/585534/9136475/d8ba8bf6-3ce4-11e5-807c-5346e33c971a.png" /><br><sub><a href="http://www.volexity.com/blog/?p=33">"Compromised Pro-Democratic Hong Kong Websites"</a>, volexity.com.</sub><br><sup>uBlock Origin shown just as a reminder on how to block 3rd-party <iframe> tags.</sup></p>
|
||||
|
||||
Simply blocking 3rd-party `<iframe>` by default foils such exploit.
|
||||
**Simply blocking 3rd-party `<iframe>` by default foils such exploit.**
|
||||
|
||||
In the above case, blocking 3rd-party scripts would have been even better, as the malicious code would have been prevented from creating the malicious `<iframe>` in the first place. But for users with low tolerance to site breakage, blocking 3rd-party `<iframe>` by default (i.e. on all sites by default) is really the best solution.
|
||||
|
||||
|
|
@ -26,7 +26,7 @@ Blocking 3rd-party `iframe` tags will typically cause little web page breakage,
|
|||
|
||||
Ultimately, if a site breaks because it really does need legitimate 3rd-party `<iframe>`, then un-blocking `<iframe>` for a specific site is only one click away:
|
||||
|
||||
<p align="center"><img src="https://cloud.githubusercontent.com/assets/585534/9136522/4455038c-3ce5-11e5-9e91-e8843f15c143.png" /><br><sup>3rd-party <iframe> tags blocked by default for all sites,<br><b>except</b> for the current site (this was for github.com).</sup></p>
|
||||
<p align="center"><img src="https://cloud.githubusercontent.com/assets/585534/9136522/4455038c-3ce5-11e5-9e91-e8843f15c143.png" /><br><sup>3rd-party <iframe> tags blocked by default for all sites,<br><b>except</b> for the current site (this was for github.com) -- **using a `noop` rule**.</sup></p>
|
||||
|
||||
But even in this case, the best advice would be to actually find from which specific hostname iframe tags are required, and to create a `noop` rule *only* for this hostname, rather than unblock all 3rd-party `iframe` tags on the site -- though this approach is better suited to advanced users.
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue